Cyber Resilience

CVE-2022-25809

CriticalPublic PoC

Published: 24 February 2022

Published
24 February 2022
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0745 91.9th percentile
Risk Priority 24 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2022-25809 is a critical-severity an unspecified weakness vulnerability in Amazon Echo Dot. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 8.1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis

The vulnerability CVE-2022-25809 is an improper neutralization of audio output affecting 3rd and 4th Generation Amazon Echo Dot devices. It enables arbitrary voice command execution on the devices through a malicious skill for remote attackers or by pairing a malicious Bluetooth device for physically proximate attackers, referred to as an "Alexa versus Alexa (AvA)" attack.

Remote or physically proximate attackers can exploit the issue without authentication or user interaction to execute arbitrary commands, resulting in a CVSS 3.1 score of 9.8 with high impact on confidentiality, integrity, and availability. The exploitation probability (EPSS) shows a flat trajectory at a peak of 0.0745.

The provided references point to an arXiv paper describing the attack but contain no details on official advisories, patches, or mitigation steps. No information on real-world exploitation activity is available in the supplied data.

EU & UK References

Vulnerability details

Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in…

more

the case of physically proximate attackers), aka an "Alexa versus Alexa (AvA)" attack.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

amazon
echo dot firmware
all versions

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References