CRITICAL🇵🇱 Wersja polska

CVE-2020-10275

CVSS 9.8v3.1pub. 2020-06-24upd. 2024-11-21

The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Easyrobotics Er200

    HW
    Easyrobotics
    all versions
  • Easyrobotics Er200 Firmware

    OS
    Easyrobotics
    all versions
  • Easyrobotics Er Flex

    HW
    Easyrobotics
    all versions
  • Easyrobotics Er Flex Firmware

    OS
    Easyrobotics
    all versions
  • Easyrobotics Er Lite

    HW
    Easyrobotics
    all versions
  • Easyrobotics Er Lite Firmware

    OS
    Easyrobotics
    all versions
  • Easyrobotics Er One

    HW
    Easyrobotics
    all versions
  • Easyrobotics Er One Firmware

    OS
    Easyrobotics
    all versions
  • Mobile Industrial Robots Mir100

    HW
    Mobile-Industrial-Robots
    all versions
  • Mobile Industrial Robots Mir1000

    HW
    Mobile-Industrial-Robots
    all versions
  • Mobile Industrial Robots Mir1000 Firmware

    OS
    Mobile-Industrial-Robots
    all versions
  • Mobile Industrial Robots Mir100 Firmware

    OS
    Mobile-Industrial-Robots
    ≤ 2.8.1.1
  • Mobile Industrial Robots Mir200

    HW
    Mobile-Industrial-Robots
    all versions
  • Mobile Industrial Robots Mir200 Firmware

    OS
    Mobile-Industrial-Robots
    all versions
  • Mobile Industrial Robots Mir250

    HW
    Mobile-Industrial-Robots
    all versions
  • Mobile Industrial Robots Mir250 Firmware

    OS
    Mobile-Industrial-Robots
    all versions
  • Mobile Industrial Robots Mir500

    HW
    Mobile-Industrial-Robots
    all versions
  • Mobile Industrial Robots Mir500 Firmware

    OS
    Mobile-Industrial-Robots
    all versions
  • Uvd Robots Uvd

    HW
    Uvd-Robots
    all versions
  • Uvd Robots Uvd Firmware

    OS
    Uvd-Robots
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-10276CRITICAL9.8PL ✓same product

Domyślne hasło PLC bezpieczeństwa w robotach MiR — wyłączenie zatrzymania awaryjnego

CVE-2020-10274HIGH7.1same product

The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly availab...

CVE-2020-10280HIGH7.5same product

The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP he...

CVE-2020-10277MEDIUM6.4same product

There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extrac...

CVE-2020-10269CRITICAL9.8PL ✓same vendor

Domyślne, jawne dane dostępowe do WiFi Access Point w robocie MiR