CRITICAL🇵🇱 Wersja polska

CVE-2020-10272

CVSS 9.8v3.1pub. 2020-06-24upd. 2024-11-21

MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and CVE-2020-10271, this flaw allows malicious actors to command the robot at desire.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Aliasrobotics Mir100

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir1000

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir1000 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir100 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir200

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir200 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir250

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir250 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Aliasrobotics Mir500

    HW
    Aliasrobotics
    all versions
  • Aliasrobotics Mir500 Firmware

    OS
    Aliasrobotics
    ≤ 2.8.1.1
  • Enabled Robotics Er Flex

    HW
    Enabled-Robotics
    all versions
  • Enabled Robotics Er Flex Firmware

    OS
    Enabled-Robotics
    ≤ 2.8.1.1
  • Enabled Robotics Er Lite

    HW
    Enabled-Robotics
    all versions
  • Enabled Robotics Er Lite Firmware

    OS
    Enabled-Robotics
    ≤ 2.8.1.1
  • Enabled Robotics Er One

    HW
    Enabled-Robotics
    all versions
  • Enabled Robotics Er One Firmware

    OS
    Enabled-Robotics
    ≤ 2.8.1.1
  • Mobile Industrial Robotics Er200

    HW
    Mobile-Industrial-Robotics
    all versions
  • Mobile Industrial Robotics Er200 Firmware

    OS
    Mobile-Industrial-Robotics
    ≤ 2.8.1.1
  • Uvd Robots

    HW
    Uvd-Robots
    all versions
  • Uvd Robots Firmware

    OS
    Uvd-Robots
    ≤ 2.8.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-10269CRITICAL9.8PL ✓same product

Domyślne, jawne dane dostępowe do WiFi Access Point w robocie MiR

CVE-2020-10270CRITICAL9.8PL ✓same product

Zakodowane na stałe domyślne dane uwierzytelniające w robotach MiR Fleet

CVE-2020-10271CRITICAL9.8PL ✓same product

Ekspozycja grafu obliczeniowego ROS na interfejsach sieciowych robotów MiR

CVE-2020-10279CRITICAL9.8PL ✓same product

Niebezpieczne domyślne konfiguracje Ubuntu w kontrolerach robotów MiR

CVE-2020-10273HIGH7.5same product

MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellect...