PT-2018-10673 · Amazon · Alexa+1

Amit Ashbel

+1

·

Publicado

2018-05-30

·

Atualizado

2024-08-05

·

CVE-2018-11567

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Amazon Echo devices (affected versions not specified)
Description The reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill, allowing an attacker to obtain transcripts of speech not intended for Alexa to process. This issue involves empty output-speech reprompts, custom wildcard input slots, and logging of detected speech. If a maliciously designed skill is installed, it could capture speech spoken within the device's hearing range.
Recommendations For Amazon Echo devices, the vendor has put mitigations in place for detecting this type of skill behavior and rejects or suppresses those skills when detected. Customers do not need to take any action for these mitigations to work.

Exploit

Correção

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11567

Produtos afetados

Alexa
Amazon Echo