← Back to all advisories
Unranked

ecobee3 lite Unencrypted Data Storage

Advisory ID
L9-15-159
Category
Unencrypted Data Storage
Vendor
ecobee
Product
ecobee3 lite
Affected Version
4.5.81.200
First Published
June 28, 2021
Last Updated
January 22, 2024
Impact
Unranked

Risk Summary

The ecobee3 lite device does not use encryption on the NAND flash storage. The device firmware as well as user information is stored on the flash chip. A threat actor with physical access can extract sensitive data from the flash storage by removing the NAND flash chip and connecting directly using a parallel flash reader. With a copy of the device firmware, a threat actor can perform offline analysis to identify vulnerabilities in the device, including recovering the root password.

Technical Details

The research team demonstrated that device storage was unencrypted by desoldering and connecting directly to the NAND chip using a parallel flash reader.

The team was able to recover the content of the device. Using the recovered information, the team extracted root passwords and PINs used to access the serial console on the device.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 MigrationProduct Tour
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLWPostmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory Affairs
Why ELTON
Why ELTONProof Over ProbabilityFind the 1%Not a Pentest. Not a Scanner.MDDT MethodologyCredentialsDevice ModalitiesPricingELTON vs. Consultants
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRegulatory GuidesWebinarsThe Death of PentestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Book a Demo