CVE-2024-12078
Severity CVSS v4.0:
MEDIUM
Type:
CWE-321
Use of Hard-coded Cryptographic Key
Publication date:
23/01/2025
Last modified:
23/01/2025
Description
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
6.30
Severity 3.x
MEDIUM