CVE-2020-10279
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were granted via file creation, access race conditions, insecure home directory configurations and defaults that facilitate Denial of Service (DoS) attacks.
Affected (10)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir250 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir500 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Aliasrobotics Mir1000 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Mobile Industrial Robotics Er200 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Enabled Robotics Er Lite | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Enabled Robotics Er Flex | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Enabled Robotics Er One | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.8.1.1 |
| Running on/with | Platform Versions |
|---|---|
Uvd Robots Uvd Robots | All versions |
Related CWEs
CWE-1188
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
CWE-276
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.