#VU57190 Improper access control in Mobile Industrial Robots products - CVE-2020-10277

 

#VU57190 Improper access control in Mobile Industrial Robots products - CVE-2020-10277

Published: October 11, 2021


Vulnerability identifier: #VU57190
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-10277
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
MiR100
MiR200
MiR250
MiR500
MiR1000
MiR Fleet
Software vendor:
Mobile Industrial Robots

Description

The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the ability to boot from USB is an insecure default configuration that is changeable by integrators. An attacker with physical access can abuse this functionality to manipulate or exfiltrate data stored on the robot’s hard drive.


Remediation

Install updates from vendor's website.

External links