CRITICAL🇵🇱 Wersja polska

CVE-2020-10270

CVSS 9.8v3.1pub. 2020-06-24upd. 2024-11-21

Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Credentials to such wireless interface default to well known and widely spread users (omitted) and passwords (omitted). This information is also available in past User Guides and manuals which the vendor distributed. This flaw allows cyber attackers to take control of the robot remotely and make use of the default user interfaces MiR has created, lowering the complexity of attacks and making them available to entry-level attackers. More elaborated attacks can also be established by clearing authentication and sending network requests directly. We have confirmed this flaw in MiR100 and MiR200 but according to the vendor, it might also apply to MiR250, MiR500 and MiR1000.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Aliasrobotics Mir100

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir1000

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir1000 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir100 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir200

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir200 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir250

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir250 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir500

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir500 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Enabled Robotics Er Flex

    HW
    Enabled-Robotics
    all versions
  • Enabled Robotics Er Flex Firmware

    OS
    Enabled-Robotics
    ≤ 2.8.1.1
  • Enabled Robotics Er Lite

    HW
    Enabled-Robotics
    all versions
  • Enabled Robotics Er Lite Firmware

    OS
    Enabled-Robotics
    ≤ 2.8.1.1
  • Enabled Robotics Er One

    HW
    Enabled-Robotics
    all versions
  • Enabled Robotics Er One Firmware

    OS
    Enabled-Robotics
    ≤ 2.8.1.1
  • Mobile Industrial Robotics Er200

    HW
    Mobile-Industrial-Robotics
    all versions
  • Mobile Industrial Robotics Er200 Firmware

    OS
    Mobile-Industrial-Robotics
    ≤ 2.8.1.1
  • Uvd Robots

    HW
    Uvd-Robots
    all versions
  • Uvd Robots Firmware

    OS
    Uvd-Robots
    ≤ 2.8.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-10269CRITICAL9.8PL ✓same product

Domyślne, jawne dane dostępowe do WiFi Access Point w robocie MiR

CVE-2020-10271CRITICAL9.8PL ✓same product

Ekspozycja grafu obliczeniowego ROS na interfejsach sieciowych robotów MiR

CVE-2020-10272CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w ROS na robotach MiR — zdalne przejęcie kontroli

CVE-2020-10279CRITICAL9.8PL ✓same product

Niebezpieczne domyślne konfiguracje Ubuntu w kontrolerach robotów MiR

CVE-2020-10273HIGH7.5same product

MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellect...