CVE-2018-17933

HIGH

VGo Robot Firmware 3.0.3.52164 3.0.3.53662 - Improper Authorization

Title source: llm
STIX 2.1

Description

VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execute commands that are outside the scope of their privileges and within the scope of an admin account. If an attacker has access to VGo XAMPP Client credentials, they may be able to execute admin commands on the connected robot.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-114-01

Scores

CVSS v3 8.8
EPSS 0.0121
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-285
Status published
Products (2)
vecna/vgo_firmware 3.0.3.52164
vecna/vgo_firmware 3.0.3.53662
Published Oct 30, 2018
Tracked Since Feb 18, 2026