Improper access control in Mobile Industrial Robots products - CVE-2020-10277

 

Improper access control in Mobile Industrial Robots products - CVE-2020-10277

Published: October 11, 2021


Vulnerability identifier: #VU57190
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10277
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the ability to boot from USB is an insecure default configuration that is changeable by integrators. An attacker with physical access can abuse this functionality to manipulate or exfiltrate data stored on the robot’s hard drive.


Affected software

MiR100
MiR200
MiR250
MiR500
MiR1000
MiR Fleet

How to mitigate CVE-2020-10277

Install updates from vendor's website.

MiR100 - update to 2.10.2.1
MiR200 - update to 2.10.2.1
MiR250 - update to 2.10.2.1
MiR500 - update to 2.10.2.1
MiR1000 - update to 2.10.2.1
MiR Fleet - update to 2.10.2.1

External References

Related Security Bulletins