CVE-2020-10273
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.
Affected (10)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir250 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir500 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir1000 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Mobile Industrial Robotics Er200 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Enabled Robotics Er Lite | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Enabled Robotics Er Flex | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Enabled Robotics Er One | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Uvd Robots Uvd Robots | All versions |
Related CWEs
CWE-311
Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
CWE-312
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
References (2)
Source: cve@aliasrobotics.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Timeline
No history available yet.