CVE-2020-10272

MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and CVE-2020-10271, this flaw allows malicious actors to command the robot at desire.
References
Link Resource
https://github.com/aliasrobotics/RVD/issues/2554 Exploit Third Party Advisory
https://github.com/aliasrobotics/RVD/issues/2554 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:aliasrobotics:mir100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aliasrobotics:mir100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:aliasrobotics:mir200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aliasrobotics:mir200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:aliasrobotics:mir250_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aliasrobotics:mir250:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:aliasrobotics:mir500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aliasrobotics:mir500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:aliasrobotics:mir1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:aliasrobotics:mir1000:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mobile-industrial-robotics:er200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mobile-industrial-robotics:er200:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:enabled-robotics:er-lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:enabled-robotics:er-lite:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:enabled-robotics:er-flex_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:enabled-robotics:er-flex:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:enabled-robotics:er-one_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:enabled-robotics:er-one:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:uvd-robots:uvd_robots_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:uvd-robots:uvd_robots:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-06-24 05:15

Updated : 2024-11-21 04:55


NVD link : CVE-2020-10272

Mitre link : CVE-2020-10272

CVE.ORG link : CVE-2020-10272


JSON object : View

Products Affected

mobile-industrial-robotics

  • er200_firmware
  • er200

enabled-robotics

  • er-flex_firmware
  • er-flex
  • er-lite_firmware
  • er-one
  • er-one_firmware
  • er-lite

aliasrobotics

  • mir100
  • mir1000_firmware
  • mir200_firmware
  • mir250_firmware
  • mir500
  • mir200
  • mir1000
  • mir100_firmware
  • mir500_firmware
  • mir250

uvd-robots

  • uvd_robots
  • uvd_robots_firmware
CWE
CWE-306

Missing Authentication for Critical Function