Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow an attacker to reset passwords for the controller.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HUniversal Robots Cb3.1
HWUniversal-Robotsall versionsUniversal Robots Cb3.1 Firmware
OSUniversal-Robots3.4.5-100
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2018-10635CRITICAL9.8PL ✓same product
Universal Robots CB 3.1 — nieautoryzowane zdalne wykonanie kodu przez porty URScript
CVE-2020-10265CRITICAL9.4PL ✓same vendor
Brak uwierzytelnienia w serwerze DashBoard robotów Universal Robots
CVE-2020-10264HIGH8.8same vendor
CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Re...
CVE-2020-10266HIGH8.1same vendor
UR+ (Universal Robots+) is a platform of hardware and software component sellers, for Universal Robots robots....
CVE-2020-10267HIGH7.5same vendor
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not ...