Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.47% | — | Neatorobotics Botvac D4 Connected FirmwareNeatorobotics Botvac D6 Connected FirmwareNeatorobotics Botvac D5 Connected FirmwareNeatorobotics Botvac D7 Connected Firmware+3 | 23/2/2019 | 17/6/2026 | Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB serial port. Although a power cycle occurs, this does not completely… | |
| Modificada | Media (5.3) | 0.68% | — | Neatorobotics Botvac D4 Connected FirmwareNeatorobotics Botvac D6 Connected FirmwareNeatorobotics Botvac D5 Connected FirmwareNeatorobotics Botvac D7 Connected Firmware+1 | 18/9/2018 | 17/6/2026 | An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sent to /bin/webserver on port 8081) if they already have an active session. Commands like forward, back, arc-left, arc-right, pivot-left, and pivot-right are executed even though the web socket replies… | |
| Modificada | Baja (2.4) | 0.17% | — | Neatorobotics Botvac D4 Connected FirmwareNeatorobotics Botvac D6 Connected FirmwareNeatorobotics Botvac D5 Connected FirmwareNeatorobotics Botvac D7 Connected Firmware+2 | 18/9/2018 | 17/6/2026 | An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom… |