← Back to all advisories
Unranked

ecobee3 lite Unencrypted Data Storage

Advisory ID
L9-15-159
Category
Unencrypted Data Storage
Vendor
ecobee
Product
ecobee3 lite
Affected Version
4.5.81.200
First Published
June 28, 2021
Last Updated
January 22, 2024
Impact
Unranked

Risk Summary

The ecobee3 lite device does not use encryption on the NAND flash storage. The device firmware as well as user information is stored on the flash chip. A threat actor with physical access can extract sensitive data from the flash storage by removing the NAND flash chip and connecting directly using a parallel flash reader. With a copy of the device firmware, a threat actor can perform offline analysis to identify vulnerabilities in the device, including recovering the root password.

Technical Details

The research team demonstrated that device storage was unencrypted by desoldering and connecting directly to the NAND chip using a parallel flash reader.

The team was able to recover the content of the device. Using the recovered information, the team extracted root passwords and PINs used to access the serial console on the device.

Questions

Common questions about ecobee3 lite unencrypted data storage.

What is the ecobee3 lite unencrypted data storage issue?

The ecobee3 lite does not encrypt its NAND flash storage, and both the device firmware and user information are held on that chip. Advisory L9-15-159 covers version 4.5.81.200. Anyone who can remove the flash chip and read it directly can pull sensitive data off the device.

Does the ecobee3 lite storage issue require physical access?

Yes. The advisory describes a threat actor with physical access extracting data by removing the NAND flash chip and connecting to it directly with a parallel flash reader. The research team demonstrated this by desoldering the chip and reading its contents off the board.

What did researchers recover from the ecobee3 lite flash chip?

The team recovered the contents of the device and, from that, extracted root passwords and the PINs used to access the serial console. The advisory also notes that a copy of the firmware lets a threat actor run offline analysis to find further vulnerabilities in the device.

Why does unencrypted storage matter if the attacker already has the device?

Unencrypted storage on the ecobee3 lite exposes the firmware as well as user data. With a copy of the firmware, a threat actor can run offline analysis, identify vulnerabilities and recover the root password. A separate advisory, L9-15-160, records that those default root credentials are the same across all ecobee3 lite devices.

How is the ecobee3 lite unencrypted storage advisory rated?

Advisory L9-15-159 lists impact as Unranked and the category as Unencrypted Data Storage. It was first published on June 28, 2021 and last updated on January 22, 2024, against ecobee3 lite version 4.5.81.200. No fixed version is named on the advisory.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 MigrationProduct Tour
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA-Compliant RatingsVerified ExploitabilityELTON vs. Legacy TestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Meet ELTON