CVE-2017-8867
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 use AES-128 with ECB mode to encrypt voice traffic between the device and remote server, allowing a malicious user to map encrypted traffic to a particular AES key index and gaining further access to eavesdrop on privacy-sensitive voice communication of a child and their Dino device.
Published:Dec 11, 2017
Last Modified:Apr 20, 2025
EPS:Dec 11, 2017
EPSS Score:0.00251
CVSS Score:5.9
Affected Products
Vendor
Product
Action
Vendor
Cognitoys
Product
Stemosaur
Cognitoys
Stemosaur
Vendor
Cognitoys
Product
Stemosaur Firmware
Cognitoys
Stemosaur Firmware
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
