Back to overview

CVE-2020-10272

CRITICAL
10.0
CVSS 3.0
Description
MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and CVE-2020-10271, this flaw allows malicious actors to command the robot at desire.

Metadata

CVE ID
CVE-2020-10272
State
PUBLISHED
Assigner
Alias
Reserved
2020-03-10 00:00 UTC
Published
2020-06-24 04:35 UTC
Last updated
2024-09-17 01:32 UTC
Primary CWE
CWE-306
CWE-306
Vendor / Product
Mobile Industrial Robots A/S / MiR100
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
Mobile Industrial Robots A/S MiR100 v2.8.1.1 and before
Weakness (CWE)
CWESourceDescription
CWE-306 cna CWE-306
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview