#VU57190 Improper access control in Mobile Industrial Robots products - CVE-2020-10277


Vulnerability identifier: #VU57190

Vulnerability risk: Low

CVSSv4.0: 1.9 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2020-10277

CWE-ID: CWE-284

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
MiR100
Hardware solutions / Firmware
MiR200
Hardware solutions / Firmware
MiR250
Hardware solutions / Firmware
MiR500
Hardware solutions / Firmware
MiR1000
Hardware solutions / Firmware
MiR Fleet
Hardware solutions / Firmware

Vendor: Mobile Industrial Robots

Description

The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the ability to boot from USB is an insecure default configuration that is changeable by integrators. An attacker with physical access can abuse this functionality to manipulate or exfiltrate data stored on the robot’s hard drive.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

MiR100: before 2.10.2.1

MiR200: before 2.10.2.1

MiR250: before 2.10.2.1

MiR500: before 2.10.2.1

MiR1000: before 2.10.2.1

MiR Fleet: before 2.10.2.1


External links
https://us-cert.cisa.gov/ics/advisories/icsa-21-280-02
https://github.com/aliasrobotics/RVD/issues/2562


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability