MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is the result of a bad set up and can be mitigated by appropriately configuring ROS and/or applying custom patches as appropriate. Currently, the ROS computational graph can be accessed fully from the wired exposed ports. In combination with other flaws such as CVE-2020-10269, the computation graph can also be fetched and interacted from wireless networks. This allows a malicious operator to take control of the ROS logic and correspondingly, the complete robot given that MiR's operations are centered around the framework (ROS).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAliasrobotics Mir100
HWAliasroboticsall versionsAliasrobotics Mir1000
HWAliasroboticsall versionsAliasrobotics Mir1000 Firmware
OSAliasrobotics≤ 2.8.1.1Aliasrobotics Mir100 Firmware
OSAliasrobotics≤ 2.8.1.1Aliasrobotics Mir200
HWAliasroboticsall versionsAliasrobotics Mir200 Firmware
OSAliasrobotics≤ 2.8.1.1Aliasrobotics Mir250
HWAliasroboticsall versionsAliasrobotics Mir250 Firmware
OSAliasrobotics≤ 2.8.1.1Aliasrobotics Mir500
HWAliasroboticsall versionsAliasrobotics Mir500 Firmware
OSAliasrobotics≤ 2.8.1.1Enabled Robotics Er Flex
HWEnabled-Roboticsall versionsEnabled Robotics Er Flex Firmware
OSEnabled-Robotics≤ 2.8.1.1Enabled Robotics Er Lite
HWEnabled-Roboticsall versionsEnabled Robotics Er Lite Firmware
OSEnabled-Robotics≤ 2.8.1.1Enabled Robotics Er One
HWEnabled-Roboticsall versionsEnabled Robotics Er One Firmware
OSEnabled-Robotics≤ 2.8.1.1Mobile Industrial Robotics Er200
HWMobile-Industrial-Roboticsall versionsMobile Industrial Robotics Er200 Firmware
OSMobile-Industrial-Robotics≤ 2.8.1.1Uvd Robots
HWUvd-Robotsall versionsUvd Robots Firmware
OSUvd-Robots≤ 2.8.1.1
Related vulnerabilities
Domyślne, jawne dane dostępowe do WiFi Access Point w robocie MiR
Zakodowane na stałe domyślne dane uwierzytelniające w robotach MiR Fleet
Brak uwierzytelnienia w ROS na robotach MiR — zdalne przejęcie kontroli
Niebezpieczne domyślne konfiguracje Ubuntu w kontrolerach robotów MiR
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellect...