← Back to all advisories
Unranked

Remote Denial of Service of ecobee3 lite

Advisory ID
L9-15-163
Category
Null Dereference
Vendor
ecobee
Product
ecobee3 lite
Affected Version
4.5.81.200
First Published
June 28, 2021
Last Updated
January 22, 2024
Impact
Unranked

Risk Summary

A threat actor sharing the same network as the ecobee3 can craft a malicious HTTP request which will cause the device to crash and reboot.

Technical Details

The Wireless Access Configuration (WAC) server used to connect the ecobee3 device to WiFi using an Apple device crashes when a specially crafted web request is received.

A threat actor can send a POST request to the endpoint http://<host>:1200/config and omit the 'Content-Type' header, which causes the 'HKProcessConfig ==> memcpy' function to read from address space 0x00000000, causing the main application (idtm) to crash. Once a crash has occurred the 'watchdog' will cause the device to reset.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 MigrationProduct Tour
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLWPostmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory Affairs
Why ELTON
Why ELTONProof Over ProbabilityFind the 1%Not a Pentest. Not a Scanner.MDDT MethodologyCredentialsDevice ModalitiesPricingELTON vs. Consultants
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRegulatory GuidesWebinarsThe Death of PentestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Book a Demo