CVE-2018-11567
CVE-2018-11567 is a low-severity vulnerability in Amazon Echo Show Firmware with a CVSS 3.x base score of 3.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-384.
Key facts
- Severity: Low (CVSS 3.x base score 3.3)
- CVSS v2: 4.3
- EPSS exploit prediction: 1% (64th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-384
- Affected product: Amazon Echo Show Firmware
- Published:
- Last modified:
Description
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an additional 8 seconds for input; if the user still does not respond, the microphone is then turned off. The vulnerability involves empty output-speech reprompts, custom wildcard ("gibberish") input slots, and logging of detected speech. If a maliciously designed skill is installed, an attacker could obtain transcripts of speech not intended for Alexa to process, but simply spoken within the device's hearing range. NOTE: The vendor states "Customer trust is important to us and we take security and privacy seriously. We have put mitigations in place for detecting this type of skill behavior and reject or suppress those skills when we do. Customers do not need to take any action for these mitigations to work.
Frequently asked questions
- What is CVE-2018-11567?
- Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an additional 8 seconds for input; if the user still does not respond, the microphone is then turned off. The vulnerability involves empty output-speech reprompts, custom wildcard ("gibberish") input slots, and logging of detected speech. If a maliciously designed skill is installed, an attacker could obtain transcripts of speech not intended for Alexa to process, but simply spoken within the device's hearing range. NOTE: The vendor states "Customer trust is important to us and we take security and privacy seriously. We have put mitigations in place for detecting this type of skill behavior and reject or suppress those skills when we do. Customers do not need to take any action for these mitigations to work.
- How severe is CVE-2018-11567?
- CVE-2018-11567 has a CVSS 3.x base score of 3.3, rated low severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2018-11567 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (64th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-11567?
- CVE-2018-11567 primarily affects Amazon Echo Show Firmware. In total, 5 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2018-11567?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2018-11567 published?
- CVE-2018-11567 was published on 2018-05-30 and last updated on 2026-06-17.
References
- https://info.checkmarx.com/hubfs/Amazon_Echo_Research.pdf
- https://www.checkmarx.com/2018/04/25/eavesdropping-with-amazon-alexa/
- https://www.wired.com/story/amazon-echo-alexa-skill-spying/
- https://www.yahoo.com/news/amazon-alexa-bug-let-hackers-104609600.html
Affected products (5)
- cpe:2.3:o:amazon:echo_show_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:amazon:echo_plus_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:amazon:echo_dot_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:amazon:echo_spot_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:amazon:echo_firmware:*:*:*:*:*:*:*:*
Other CWE-384 (Session Fixation) vulnerabilities
- CVE-2024-11317 — Critical (CVSS 10.0): Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an…
- CVE-2024-38513 — Critical (CVSS 10.0): Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a…
- CVE-2021-20151 — Critical (CVSS 10.0): Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's…
- CVE-2026-18527 — Critical (CVSS 9.9): IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker…
- CVE-2026-102489 — Critical (CVSS 9.8): Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the…
- CVE-2026-92609 — Critical (CVSS 9.8): Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an…