#VU57191 Improper access control in Mobile Industrial Robots products - CVE-2020-10278
Published: October 11, 2021
Vulnerability identifier: #VU57191
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-10278
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
MiR100
MiR200
MiR250
MiR500
MiR1000
MiR Fleet
MiR100
MiR200
MiR250
MiR500
MiR1000
MiR Fleet
Software vendor:
Mobile Industrial Robots
Mobile Industrial Robots
Description
The vulnerability allows an attacker with physical access to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the lack of a BIOS password is an insecure default configuration, changeable by integrators.
Remediation
Install updates from vendor's website.