CVE-2022-25809

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/02/2022
Last modified:
08/08/2023

Description

Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus Alexa (AvA)" attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:amazon:echo_dot_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amazon:echo_dot:3.0:*:*:*:*:*:*:*
cpe:2.3:h:amazon:echo_dot:4.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools