漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ECOVACS lawnmowers and vacuums static BLE GATT encryption key
Vulnerability Description
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
使用硬编码的密码学密钥
Vulnerability Title
ECOVACS robot lawnmowers和vacuums 安全漏洞
Vulnerability Description
ECOVACS robot vacuums和ECOVACS robot lawnmowers都是中国科沃斯(ECOVACS)公司的产品。ECOVACS robot vacuums是一系列吸尘器。ECOVACS robot lawnmowers是一系列割草机。 ECOVACS robot lawnmowers和vacuums存在安全漏洞,该漏洞源于使用共享静态密钥加密BLE消息,导致未认证的攻击者在BLE范围内可控制设备。
CVSS Information
N/A
Vulnerability Type
N/A