Cleartext Anti-theft PIN Vulnerability in ECOVACS Robot Lawnmowers
CVE-2024-12079
4.8MEDIUM
What is CVE-2024-12079?
ECOVACS robot lawnmowers are at risk due to their practice of storing anti-theft PINs in cleartext on the device's filesystem. This vulnerability allows attackers who physically access the device to effortlessly read the stored PIN, leading to potential theft and the ability to reset the anti-theft mechanism. Users of ECOVACS lawnmowers should be aware of this security flaw and take appropriate measures to safeguard their devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Unspecified robots *
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
