ecobee records
4 published records for vendor ecobee.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-476 NULL Pointer Dereference1
- CWE-787 Out-of-bounds Write1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-27952No exploit | Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device.ecobee · ecobee3 lite firmware · CWE-798 | Critical9.8 | — | 1.1% | Aug 3, 2021 |
32Monitor | CVE-2021-27954No exploit | A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wirelecobee · ecobee3 lite firmware · CWE-787 | High8.2 | — | 0.9% | Aug 3, 2021 |
31Monitor | CVE-2021-27953No exploit | A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process.ecobee · ecobee3 lite firmware · CWE-476 | High7.5 | — | 1.7% | Aug 3, 2021 |
30Monitor | CVE-2018-6402No exploit | Ecobee Ecobee4 4.2.0.171 devices can be forced to deauthenticate and connect to an unencrypted Wi-Fi network with the same SSID, even if theecobee · ecobee4 firmware · CWE-327 | High7.5 | — | 0.2% | Apr 14, 2020 |
- CVE-2021-2795239Monitor
Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device.
CriticalCVSS 9.8No exploitEPSS 1%ecobee · ecobee3 lite firmwareAug 3, 2021
- CVE-2021-2795432Monitor
A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wirel
HighCVSS 8.2No exploitEPSS 1%ecobee · ecobee3 lite firmwareAug 3, 2021
- CVE-2021-2795331Monitor
A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process.
HighCVSS 7.5No exploitEPSS 2%ecobee · ecobee3 lite firmwareAug 3, 2021
- CVE-2018-640230Monitor
Ecobee Ecobee4 4.2.0.171 devices can be forced to deauthenticate and connect to an unencrypted Wi-Fi network with the same SSID, even if the
HighCVSS 7.5No exploitEPSS 0%ecobee · ecobee4 firmwareApr 14, 2020