There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.
oryginał ENCVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:HEasyrobotics Er200
HWEasyroboticswszystkie wersjeEasyrobotics Er200 Firmware
OSEasyroboticswszystkie wersjeEasyrobotics Er Flex
HWEasyroboticswszystkie wersjeEasyrobotics Er Flex Firmware
OSEasyroboticswszystkie wersjeEasyrobotics Er Lite
HWEasyroboticswszystkie wersjeEasyrobotics Er Lite Firmware
OSEasyroboticswszystkie wersjeEasyrobotics Er One
HWEasyroboticswszystkie wersjeEasyrobotics Er One Firmware
OSEasyroboticswszystkie wersjeMobile Industrial Robots Mir100
HWMobile-Industrial-Robotswszystkie wersjeMobile Industrial Robots Mir1000
HWMobile-Industrial-Robotswszystkie wersjeMobile Industrial Robots Mir1000 Firmware
OSMobile-Industrial-Robotswszystkie wersjeMobile Industrial Robots Mir100 Firmware
OSMobile-Industrial-Robots≤ 2.8.1.1Mobile Industrial Robots Mir200
HWMobile-Industrial-Robotswszystkie wersjeMobile Industrial Robots Mir200 Firmware
OSMobile-Industrial-Robotswszystkie wersjeMobile Industrial Robots Mir250
HWMobile-Industrial-Robotswszystkie wersjeMobile Industrial Robots Mir250 Firmware
OSMobile-Industrial-Robotswszystkie wersjeMobile Industrial Robots Mir500
HWMobile-Industrial-Robotswszystkie wersjeMobile Industrial Robots Mir500 Firmware
OSMobile-Industrial-Robotswszystkie wersjeUvd Robots Uvd
HWUvd-Robotswszystkie wersjeUvd Robots Uvd Firmware
OSUvd-Robotswszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
LPE
Powiązane podatności
CVE-2020-10275CRITICAL9.8PL ✓ten sam produkt
Słabe tokeny REST API w robotach MiR — przewidywalny mechanizm autoryzacji
CVE-2020-10276CRITICAL9.8PL ✓ten sam produkt
Domyślne hasło PLC bezpieczeństwa w robotach MiR — wyłączenie zatrzymania awaryjnego
CVE-2020-10274HIGH7.1ten sam produkt
The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly availab...
CVE-2020-10280HIGH7.5ten sam produkt
The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP he...
CVE-2020-10269CRITICAL9.8PL ✓ten sam vendor
Domyślne, jawne dane dostępowe do WiFi Access Point w robocie MiR