CVE-2021-37436
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a factory reset. Also, the vendor has reportedly indicated that they are working on mitigations.
Unos dispositivos Amazon Echo Dot versiones hasta 02-07-2021 a veces permiten a atacantes, que tienen acceso físico a un dispositivo después de un restablecimiento de fábrica, obtener información confidencial por medio de una serie de complejos ataques de hardware y software. NOTA: según se informa, hubo declaraciones de marketing del proveedor sobre la eliminación segura de contenido personal por medio de un restablecimiento de fábrica. Además, el proveedor ha reportado que está trabajando en la mitigación
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-24 CVE Reserved
- 2021-07-24 CVE Published
- 2024-04-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://arstechnica.com/gadgets/2021/07/passwords-in-amazon-echo-dots-live-on-even-after-you-factory-reset-them | Third Party Advisory | |
https://dl.acm.org/doi/pdf/10.1145/3448300.3467820 | Technical Description | |
https://news.ycombinator.com/item?id=27943730 | Third Party Advisory | |
https://www.cpomagazine.com/data-privacy/is-it-possible-to-make-iot-devices-private-amazon-echo-dot-does-not-wipe-personal-content-after-factory-reset | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Amazon Search vendor "Amazon" | Echo Dot Firmware Search vendor "Amazon" for product "Echo Dot Firmware" | <= 2021-07-02 Search vendor "Amazon" for product "Echo Dot Firmware" and version " <= 2021-07-02" | - |
Affected
| in | Amazon Search vendor "Amazon" | Echo Dot Search vendor "Amazon" for product "Echo Dot" | - | - |
Safe
|