← Voltar para CVEs
CVE-2022-2675
MEDIUM6.5
Descricao
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.
Detalhes CVE
Pontuacao CVSS v3.16.5
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vetor de ataqueADJACENT_NETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado8/5/2022
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
unitree:go_1unitree:go_1_firmware
Fraquezas (CWE)
CWE-285
Referencias
https://fccid.io/2A5PE-YUSHU001/Users-Manual/User-Manual-5810729(cve@rapid7.com)
https://twitter.com/d0tslash/status/1555326302462394370(cve@rapid7.com)
https://fccid.io/2A5PE-YUSHU001/Users-Manual/User-Manual-5810729(af854a3a-2127-422b-91ae-364da2661108)
https://twitter.com/d0tslash/status/1555326302462394370(af854a3a-2127-422b-91ae-364da2661108)
https://www.mybotshop.de/Datasheet/Unitree_A1_User_Manual_v1.0.pdf(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.