CVE-2020-10273
moderate-risk
Published 2020-06-24
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.
Do I need to act?
-
0.12% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (10)
Mir100 Firmware
Mir200 Firmware
Mir250 Firmware
Mir500 Firmware
Mir1000 Firmware
Er200 Firmware
Er-Lite Firmware
Er-Flex Firmware
Er-One Firmware
Uvd Robots Firmware
Affected Vendors
References (2)
Issue Tracking
https://github.com/aliasrobotics/RVD/issues/2560
Issue Tracking
https://github.com/aliasrobotics/RVD/issues/2560
43
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
1/34 · Minimal
Exposure
16/34 · Moderate