Description
An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sent to /bin/webserver on port 8081) if they already have an active session. Commands like forward, back, arc-left, arc-right, pivot-left, and pivot-right are executed even though the web socket replies with { "message" : "invalid authorization header" }. Without an active session, commands are still interpreted, but (except for eco-on and eco-off) have no effect, since without active driving, a driving direction does not change anything.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-8952 | An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sent to /bin/webserver on port 8081) if they already have an active session. Commands like forward, back, arc-left, arc-right, pivot-left, and pivot-right are executed even though the web socket replies with { "message" : "invalid authorization header" }. Without an active session, commands are still interpreted, but (except for eco-on and eco-off) have no effect, since without active driving, a driving direction does not change anything. |
References
History
No history.
Subscriptions
Neatorobotics
Subscribe
Botvac D3 Connected
Subscribe
Botvac D3 Connected Firmware
Subscribe
Botvac D4 Connected
Subscribe
Botvac D4 Connected Firmware
Subscribe
Botvac D5 Connected
Subscribe
Botvac D5 Connected Firmware
Subscribe
Botvac D6 Connected
Subscribe
Botvac D6 Connected Firmware
Subscribe
Botvac D7 Connected
Subscribe
Botvac D7 Connected Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T02:42:40.739Z
Reserved: 2018-09-18T00:00:00.000Z
Link: CVE-2018-17178
No data.
Status : Modified
Published: 2018-09-18T18:29:09.600
Modified: 2024-11-21T03:54:01.510
Link: CVE-2018-17178
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD