TROYANOSYVIRUS
Retour aux CVEs

CVE-2020-10276

CRITICAL
9.8

Description

The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation and any other components dependent on the laser scanner are not affected (thus it is hard to detect before something happens) though the laser scanner configuration can also be affected altering further the safety of the device.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie6/24/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

easyrobotics:er-flexeasyrobotics:er-flex_firmwareeasyrobotics:er-liteeasyrobotics:er-lite_firmwareeasyrobotics:er-oneeasyrobotics:er-one_firmwareeasyrobotics:er200easyrobotics:er200_firmwaremobile-industrial-robots:mir100mobile-industrial-robots:mir1000mobile-industrial-robots:mir1000_firmwaremobile-industrial-robots:mir100_firmwaremobile-industrial-robots:mir200mobile-industrial-robots:mir200_firmwaremobile-industrial-robots:mir250mobile-industrial-robots:mir250_firmwaremobile-industrial-robots:mir500mobile-industrial-robots:mir500_firmwareuvd-robots:uvduvd-robots:uvd_firmware

Faiblesses (CWE)

CWE-798CWE-798

References

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.