Vulnerabilities > Amazon > Echo DOT Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-02-24 CVE-2022-25809 Unspecified vulnerability in Amazon Echo DOT Firmware
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus Alexa (AvA)" attack.
network
low complexity
amazon
critical
9.8
2021-07-24 CVE-2021-37436 Unspecified vulnerability in Amazon Echo DOT Firmware 20180427/20210702
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks.
high complexity
amazon
4.2
2018-05-30 CVE-2018-11567 Session Fixation vulnerability in Amazon products
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill.
local
low complexity
amazon CWE-384
3.3