ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
References
Configurations
No configuration.
History
23 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-23 17:15
Updated : 2025-01-23 17:15
NVD link : CVE-2024-52330
Mitre link : CVE-2024-52330
CVE.ORG link : CVE-2024-52330
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation