HIGH🇵🇱 Wersja polska

CVE-2020-10286

CVSS 8.8v3.1pub. 2020-07-15upd. 2024-11-21

the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Ufactory Xarm 5 Lite

    HW
    Ufactory
    all versions
  • Ufactory Xarm 5 Lite Firmware

    OS
    Ufactory
    ≤ 1.5.0
  • Ufactory Xarm 6

    HW
    Ufactory
    all versions
  • Ufactory Xarm 6 Firmware

    OS
    Ufactory
    all versions
  • Ufactory Xarm 7

    HW
    Ufactory
    all versions
  • Ufactory Xarm 7 Firmware

    OS
    Ufactory
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-10285CRITICAL9.8PL ✓same product

Brute-force uwierzytelnienia w kontrolerze Ufactory xArm 5 Lite

CVE-2020-10284CRITICAL9.1PL ✓same vendor

Brak uwierzytelniania w Ufactory xArm Studio — nieautoryzowana kontrola robota