← Back to all advisories
Unranked

Remote Denial of Service of ecobee3 lite

Advisory ID
L9-15-163
Category
Null Dereference
Vendor
ecobee
Product
ecobee3 lite
Affected Version
4.5.81.200
First Published
June 28, 2021
Last Updated
January 22, 2024
Impact
Unranked

Risk Summary

A threat actor sharing the same network as the ecobee3 can craft a malicious HTTP request which will cause the device to crash and reboot.

Technical Details

The Wireless Access Configuration (WAC) server used to connect the ecobee3 device to WiFi using an Apple device crashes when a specially crafted web request is received.

A threat actor can send a POST request to the endpoint http://<host>:1200/config and omit the 'Content-Type' header, which causes the 'HKProcessConfig ==> memcpy' function to read from address space 0x00000000, causing the main application (idtm) to crash. Once a crash has occurred the 'watchdog' will cause the device to reset.

Questions

Common questions about the ecobee3 lite denial of service.

What causes the remote denial of service on the ecobee3 lite?

A threat actor on the same network as the ecobee3 can send a crafted HTTP request that crashes the device and forces a reboot. Advisory L9-15-163 traces it to the Wireless Access Configuration server, and files the category as null dereference for ecobee3 lite version 4.5.81.200.

Which request triggers the ecobee3 lite crash?

The ecobee3 lite crash is triggered by a POST request to the /config endpoint that omits the Content-Type header. The advisory states this makes the HKProcessConfig memcpy call read from address space 0x00000000, which crashes the main application, named idtm. The Wireless Access Configuration server listens on TCP port 1200.

Does the ecobee3 lite recover after the crash?

Yes. The advisory states that once a crash has occurred the watchdog will cause the device to reset. The result is a crash and reboot of the ecobee3 rather than a persistent failure, and the advisory describes no code execution from this issue.

Can the ecobee3 lite denial of service be triggered from the internet?

The advisory describes a threat actor sharing the same network as the ecobee3 sending the malicious HTTP request. It does not describe an internet facing attack path. Impact is listed as Unranked, and the advisory was first published on June 28, 2021 and last updated on January 22, 2024.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON