CVE-2020-10269
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode. Credentials to such wireless Access Point default to well known and widely spread SSID (MiR_RXXXX) and passwords (omitted). This information is also available in past User Guides and manuals which the vendor distributed. We have confirmed this flaw in MiR100 and MiR200 but it might also apply to MiR250, MiR500 and MiR1000.
Affected (10)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir250 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir500 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir1000 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Mobile Industrial Robotics Er200 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Enabled Robotics Er Lite | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Enabled Robotics Er Flex | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Enabled Robotics Er One | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Uvd Robots Uvd Robots | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.