Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill
Published May 30, 2018
3.3
LOWCVSS 3.0
EPSS 1.09%
Description
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an additional 8 seconds for input; if the user still does not respond, the microphone is then turned off. The vulnerability involves empty output-speech reprompts, custom wildcard ("gibberish") input slots, and logging of detected speech. If a maliciously designed skill is installed, an attacker could obtain transcripts of speech not intended for Alexa to process, but simply spoken within the device's hearing range. NOTE: The vendor states "Customer trust is important to us and we take security and privacy seriously. We have put mitigations in place for detecting this type of skill behavior and reject or suppress those skills when we do. Customers do not need to take any action for these mitigations to work.
Affected products
No data.
Configuration 1
- < 2018-04-27
Configuration 2
- < 2018-04-27
Configuration 3
- < 2018-04-27
Configuration 4
- < 2018-04-27
Configuration 5
- < 2018-04-27
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.09% (0.01086) | 64.07th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.09% (0.01086) | 63.79th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.10% (0.00105) | 43.22th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.10% (0.00105) | 41.95th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.10% (0.00096) | 38.79th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.04% (0.01040) | 28.32th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (4)
- https://info.checkmarx.com/hubfs/Amazon_Echo_Research.pdf x_refsource_MISCExploitThird Party Advisory
- https://www.checkmarx.com/2018/04/25/eavesdropping-with-amazon-alexa/ x_refsource_MISCThird Party Advisory
- https://www.wired.com/story/amazon-echo-alexa-skill-spying/ x_refsource_MISCPress/Media CoverageThird Party Advisory
- https://www.yahoo.com/news/amazon-alexa-bug-let-hackers-104609600.html x_refsource_MISCPress/Media CoverageThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://info.checkmarx.com/hubfs/Amazon_Echo_Research.pdf | x_refsource_MISCExploitThird Party Advisory | |
| https://www.checkmarx.com/2018/04/25/eavesdropping-with-amazon-alexa/ | x_refsource_MISCThird Party Advisory | |
| https://www.wired.com/story/amazon-echo-alexa-skill-spying/ | x_refsource_MISCPress/Media CoverageThird Party Advisory | |
| https://www.yahoo.com/news/amazon-alexa-bug-let-hackers-104609600.html | x_refsource_MISCPress/Media CoverageThird Party Advisory |
Change history (0)
No recorded changes yet.