ID

VAR-201810-0210


CVE

CVE-2018-18638


TITLE

Neato Botvac Connected Command Injection Vulnerability

Trust: 2.0

sources: CNVD: CNVD-2018-21849 // JVNDB: JVNDB-2018-013876 // CNNVD: CNNVD-201810-1241

DESCRIPTION

A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initialize endpoint. Neato Botvac Connected Contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. NeatoBotvacConnected is a vacuum robotic device from NeatoRobotics, USA. There is a command injection vulnerability in the setupAPI in NeatoBotvacConnected version 2.2.0. Neato Botvac Connected is a vacuum robot device from Neato Robotics in the United States

Trust: 2.25

sources: NVD: CVE-2018-18638 // JVNDB: JVNDB-2018-013876 // CNVD: CNVD-2018-21849 // VULHUB: VHN-129217

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

category:['industrial device']sub_category:robot

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2018-21849

AFFECTED PRODUCTS

vendor:neatoroboticsmodel:botvac connectedscope:eqversion:2.2.0

Trust: 1.0

vendor:neato roboticsmodel:botvac connectedscope:eqversion:2.2.0

Trust: 0.8

vendor:neatomodel:botvac connectedscope:eqversion:2.2.0

Trust: 0.6

sources: CNVD: CNVD-2018-21849 // JVNDB: JVNDB-2018-013876 // NVD: CVE-2018-18638

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-18638
value: HIGH

Trust: 1.0

NVD: CVE-2018-18638
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-21849
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201810-1241
value: HIGH

Trust: 0.6

VULHUB: VHN-129217
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-18638
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-21849
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-129217
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-18638
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-21849 // VULHUB: VHN-129217 // JVNDB: JVNDB-2018-013876 // CNNVD: CNNVD-201810-1241 // NVD: CVE-2018-18638

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.1

problemtype:CWE-77

Trust: 0.9

sources: VULHUB: VHN-129217 // JVNDB: JVNDB-2018-013876 // NVD: CVE-2018-18638

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201810-1241

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-201810-1241

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-013876

PATCH

title:Top Pageurl:https://www.neatorobotics.com/

Trust: 0.8

sources: JVNDB: JVNDB-2018-013876

EXTERNAL IDS

db:NVDid:CVE-2018-18638

Trust: 3.2

db:JVNDBid:JVNDB-2018-013876

Trust: 0.8

db:CNNVDid:CNNVD-201810-1241

Trust: 0.7

db:CNVDid:CNVD-2018-21849

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULHUBid:VHN-129217

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2018-21849 // VULHUB: VHN-129217 // JVNDB: JVNDB-2018-013876 // CNNVD: CNNVD-201810-1241 // NVD: CVE-2018-18638

REFERENCES

url:https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2018/march/security-in-a-vacuum-hacking-the-neato-botvac-connected-part-1/

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2018-18638

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-18638

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2018-21849 // VULHUB: VHN-129217 // JVNDB: JVNDB-2018-013876 // CNNVD: CNNVD-201810-1241 // NVD: CVE-2018-18638

SOURCES

db:OTHERid: -
db:CNVDid:CNVD-2018-21849
db:VULHUBid:VHN-129217
db:JVNDBid:JVNDB-2018-013876
db:CNNVDid:CNNVD-201810-1241
db:NVDid:CVE-2018-18638

LAST UPDATE DATE

2025-01-30T19:37:00.628000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-21849date:2018-10-26T00:00:00
db:VULHUBid:VHN-129217date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-013876date:2019-03-05T00:00:00
db:CNNVDid:CNNVD-201810-1241date:2019-10-23T00:00:00
db:NVDid:CVE-2018-18638date:2024-11-21T03:56:16.657

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-21849date:2018-10-26T00:00:00
db:VULHUBid:VHN-129217date:2018-10-24T00:00:00
db:JVNDBid:JVNDB-2018-013876date:2019-03-05T00:00:00
db:CNNVDid:CNNVD-201810-1241date:2018-10-25T00:00:00
db:NVDid:CVE-2018-18638date:2018-10-24T22:29:02.043