9
CVSSv2

CVE-2022-25809

Published: 24/02/2022 Updated: 08/08/2023
CVSS v2 Base Score: 9 | Impact Score: 8.5 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 801
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C

Vulnerability Summary

Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus Alexa (AvA)" attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

amazon echo_dot_firmware -

Recent Articles

Amazon Alexa can be hijacked via commands from own speaker
The Register • Gareth Corfield • 01 Jan 1970

Get our weekly newsletter This isn't the artificial intelligence we were promised

Without a critical update, Amazon Alexa devices could wake themselves up and start executing audio commands issued by a remote attacker, according to infosec researchers at Royal Holloway, University of London. By exploiting a now-patched vulnerability, a malicious person with access to a smart speaker could broadcast commands to itself or to other smart speakers nearby, allowing said miscreant to start "smart appliances within the household, buy unwanted items, tamper [with] linked calendars an...