CVE-2020-10279
CRITICALMiR and ER Robot Firmware < 2.8.1.1 - Race Condition and Privilege Escalation via Insecure Ubuntu Defaults
Title source: llmDescription
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were granted via file creation, access race conditions, insecure home directory configurations and defaults that facilitate Denial of Service (DoS) attacks.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_confirm
https://github.com/aliasrobotics/RVD/issues/2569
Scores
CVSS v3
9.8
EPSS
0.0097
EPSS Percentile
56.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-362
CWE-276
CWE-1188
Status
published
Products (10)
aliasrobotics/mir1000_firmware
< 2.8.1.1
aliasrobotics/mir100_firmware
< 2.8.1.1
aliasrobotics/mir200_firmware
< 2.8.1.1
aliasrobotics/mir250_firmware
< 2.8.1.1
aliasrobotics/mir500_firmware
< 2.8.1.1
enabled-robotics/er-flex_firmware
< 2.8.1.1
enabled-robotics/er-lite_firmware
< 2.8.1.1
enabled-robotics/er-one_firmware
< 2.8.1.1
mobile-industrial-robotics/er200_firmware
< 2.8.1.1
uvd-robots/uvd_robots_firmware
< 2.8.1.1
Published
Jun 24, 2020
Tracked Since
Feb 18, 2026