CVE-2020-10279

CRITICAL

MiR and ER Robot Firmware < 2.8.1.1 - Race Condition and Privilege Escalation via Insecure Ubuntu Defaults

Title source: llm
STIX 2.1

Description

MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were granted via file creation, access race conditions, insecure home directory configurations and defaults that facilitate Denial of Service (DoS) attacks.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_confirm
https://github.com/aliasrobotics/RVD/issues/2569

Scores

CVSS v3 9.8
EPSS 0.0097
EPSS Percentile 56.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362 CWE-276 CWE-1188
Status published
Products (10)
aliasrobotics/mir1000_firmware < 2.8.1.1
aliasrobotics/mir100_firmware < 2.8.1.1
aliasrobotics/mir200_firmware < 2.8.1.1
aliasrobotics/mir250_firmware < 2.8.1.1
aliasrobotics/mir500_firmware < 2.8.1.1
enabled-robotics/er-flex_firmware < 2.8.1.1
enabled-robotics/er-lite_firmware < 2.8.1.1
enabled-robotics/er-one_firmware < 2.8.1.1
mobile-industrial-robotics/er200_firmware < 2.8.1.1
uvd-robots/uvd_robots_firmware < 2.8.1.1
Published Jun 24, 2020
Tracked Since Feb 18, 2026