Improper access control in Mobile Industrial Robots products - CVE-2020-10276

 

Improper access control in Mobile Industrial Robots products - CVE-2020-10276

Published: October 11, 2021


Vulnerability identifier: #VU57189
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10276
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to MiR robots shipped before June 2020 had default passwords set for the SICK safety PLC. A remote attacker on the local network can use the default credentials to manipulate the safety PLC, effectively disabling the emergency stop function. 


Affected software

MiR100
MiR200
MiR250
MiR500
MiR1000
MiR Fleet

How to mitigate CVE-2020-10276

Install updates from vendor's website.

MiR100 - update to 2.10.2.1
MiR200 - update to 2.10.2.1
MiR250 - update to 2.10.2.1
MiR500 - update to 2.10.2.1
MiR1000 - update to 2.10.2.1
MiR Fleet - update to 2.10.2.1

External References

Related Security Bulletins