CVE-2020-10273 PUBLISHED CVSS 7.5 HIGH

MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.

EPSS 0.12% · 31.5th percentile

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.12%
31.5th percentile

Affected Products

VendorProductVersions
uvd-robotsuvd_robots_firmware0
aliasroboticsmir1000_firmware0
aliasroboticsmir250_firmware0
enabled-roboticser-one_firmware0
aliasroboticsmir500_firmware0
aliasroboticsmir200_firmware0
enabled-roboticser-lite_firmware0
enabled-roboticser-flex_firmware0
mobile-industrial-roboticser200_firmware0
aliasroboticsmir100_firmware0
Mobile Industrial Robots A/SMiR100v2.8.1.1 and before

Timeline

References

Open in Interactive Console →