CVE-2020-16167
Summary
| CVE | CVE-2020-16167 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-07 20:15:00 UTC |
| Updated | 2020-09-02 19:15:00 UTC |
| Description | Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answering the call this way grants motor control of the temi in addition to audio/video via unspecified vectors. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Robotemi | Launcher Os | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Software Updates - temi robot | MISC | www.robotemi.com | Vendor Advisory |
| Call an Exorcist! My Robot’s Possessed! | McAfee Blogs | MISC | www.mcafee.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.