HIGH🇬🇧 English

CVE-2020-10273

CVSS 7.5v3.1pub. 2020-06-24upd. 2024-11-21

MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Aliasrobotics Mir100

    HW
    Aliasrobotics
    wszystkie wersje
  • Aliasrobotics Mir1000

    HW
    Aliasrobotics
    wszystkie wersje
  • Aliasrobotics Mir1000 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir100 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir200

    HW
    Aliasrobotics
    wszystkie wersje
  • Aliasrobotics Mir200 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir250

    HW
    Aliasrobotics
    wszystkie wersje
  • Aliasrobotics Mir250 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir500

    HW
    Aliasrobotics
    wszystkie wersje
  • Aliasrobotics Mir500 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Enabled Robotics Er Flex

    HW
    Enabled-Robotics
    wszystkie wersje
  • Enabled Robotics Er Flex Firmware

    OS
    Enabled-Robotics
    ≤ 2.8.1.1
  • Enabled Robotics Er Lite

    HW
    Enabled-Robotics
    wszystkie wersje
  • Enabled Robotics Er Lite Firmware

    OS
    Enabled-Robotics
    ≤ 2.8.1.1
  • Enabled Robotics Er One

    HW
    Enabled-Robotics
    wszystkie wersje
  • Enabled Robotics Er One Firmware

    OS
    Enabled-Robotics
    ≤ 2.8.1.1
  • Mobile Industrial Robotics Er200

    HW
    Mobile-Industrial-Robotics
    wszystkie wersje
  • Mobile Industrial Robotics Er200 Firmware

    OS
    Mobile-Industrial-Robotics
    ≤ 2.8.1.1
  • Uvd Robots

    HW
    Uvd-Robots
    wszystkie wersje
  • Uvd Robots Firmware

    OS
    Uvd-Robots
    ≤ 2.8.1.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2020-10269CRITICAL9.8PL ✓ten sam produkt

Domyślne, jawne dane dostępowe do WiFi Access Point w robocie MiR

CVE-2020-10270CRITICAL9.8PL ✓ten sam produkt

Zakodowane na stałe domyślne dane uwierzytelniające w robotach MiR Fleet

CVE-2020-10271CRITICAL9.8PL ✓ten sam produkt

Ekspozycja grafu obliczeniowego ROS na interfejsach sieciowych robotów MiR

CVE-2020-10272CRITICAL9.8PL ✓ten sam produkt

Brak uwierzytelnienia w ROS na robotach MiR — zdalne przejęcie kontroli

CVE-2020-10279CRITICAL9.8PL ✓ten sam produkt

Niebezpieczne domyślne konfiguracje Ubuntu w kontrolerach robotów MiR