ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.
References
Configurations
No configuration.
History
23 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-23 17:15
Updated : 2025-01-23 17:15
NVD link : CVE-2024-52329
Mitre link : CVE-2024-52329
CVE.ORG link : CVE-2024-52329
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation