#VU13798 Use of hard-coded credentials in SW and CB - CVE-2018-10633
Published: July 10, 2018 / Updated: July 11, 2018
SW
CB
Universal Robots
Description
The vulnerability allows a remote attacker to reset passwords for the controller on the target system.
The vulnerability exists due to the application utilizes hard-coded credentials. A remote unauthenticated attacker can reset passwords for the controller.
Remediation
Universal Robots recommends the follow remedial actions:
- Only allow trusted users physical access to the robot control box and teach pendant.
- Do not connect the robot to a network unless it is required by the application.
- Do not connect the robot directly to the internet. Use a secure network with proper firewall configuration (Ports 30001/TCP to 30003/TCP must be restricted).
- Make the private subnet where the robot network interface is exposed as small as possible.