Missing Authentication for Critical Function in Mobile Industrial Robots products - CVE-2020-10272
Published: October 11, 2021
Vulnerability identifier: #VU57187
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10272
CWE-ID: CWE-306
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to Robot Operating System (ROS) default packages are used, which expose the computational graph without any authentication. A remote attacker on the local network can take control of the robot.
Affected software
MiR100
MiR200
MiR250
MiR500
MiR1000
MiR Fleet
MiR200
MiR250
MiR500
MiR1000
MiR Fleet
How to mitigate CVE-2020-10272
Install updates from vendor's website.
MiR100 - update to 2.10.2.1
MiR200 - update to 2.10.2.1
MiR250 - update to 2.10.2.1
MiR500 - update to 2.10.2.1
MiR1000 - update to 2.10.2.1
MiR Fleet - update to 2.10.2.1
MiR200 - update to 2.10.2.1
MiR250 - update to 2.10.2.1
MiR500 - update to 2.10.2.1
MiR1000 - update to 2.10.2.1
MiR Fleet - update to 2.10.2.1