PT-2022-17534 · Amazon · Amazon Echo Dot
Daniele Sgandurra
+2
·
Published
2022-02-23
·
Updated
2023-08-08
·
CVE-2022-25809
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Amazon Echo Dot devices, 3rd and 4th Generation
Description
The issue allows for arbitrary voice command execution on affected devices. This can be achieved by a remote attacker using a malicious skill or by a physically proximate attacker pairing a malicious Bluetooth device, also known as an "Alexa versus Alexa (AvA)" attack.
Recommendations
For 3rd Generation Amazon Echo Dot devices, update the device to a version that includes a fix for this issue.
For 4th Generation Amazon Echo Dot devices, update the device to a version that includes a fix for this issue.
As a temporary workaround, consider disabling skills from untrusted sources and restricting Bluetooth pairing to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amazon Echo Dot