First published: Sat Jul 24 2021(Updated: )
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a factory reset. Also, the vendor has reportedly indicated that they are working on mitigations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Echo Dot Firmware | <=2021-07-02 | |
Amazon Echo Dot |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Amazon Echo Dot vulnerability is CVE-2021-37436.
The severity of CVE-2021-37436 is medium with a severity value of 4.2.
The affected software of CVE-2021-37436 is Amazon Echo Dot devices with firmware up to version 2021-07-02.
Attackers can exploit CVE-2021-37436 by having physical access to a device after a factory reset and performing complex hardware and software attacks.
Yes, Amazon Echo Dot devices with firmware up to version 2021-07-02 are vulnerable to CVE-2021-37436.