CVE-2020-10271

Summary

CVECVE-2020-10271
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2020-06-24 05:15:00 UTC
Updated2020-07-06 15:54:00 UTC
DescriptionMiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is the result of a bad set up and can be mitigated by appropriately configuring ROS and/or applying custom patches as appropriate. Currently, the ROS computational graph can be accessed fully from the wired exposed ports. In combination with other flaws such as CVE-2020-10269, the computation graph can also be fetched and interacted from wireless networks. This allows a malicious operator to take control of the ROS logic and correspondingly, the complete robot given that MiR's operations are centered around the framework (ROS).

Risk And Classification

Problem Types: CWE-668

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Aliasrobotics Mir100 - All All All
Hardware Aliasrobotics Mir100 - All All All
Hardware Aliasrobotics Mir1000 - All All All
Hardware Aliasrobotics Mir1000 - All All All
Operating System Aliasrobotics Mir1000 Firmware All All All All
Operating System Aliasrobotics Mir100 Firmware All All All All
Hardware Aliasrobotics Mir200 - All All All
Hardware Aliasrobotics Mir200 - All All All
Operating System Aliasrobotics Mir200 Firmware All All All All
Hardware Aliasrobotics Mir250 - All All All
Hardware Aliasrobotics Mir250 - All All All
Operating System Aliasrobotics Mir250 Firmware All All All All
Hardware Aliasrobotics Mir500 - All All All
Hardware Aliasrobotics Mir500 - All All All
Operating System Aliasrobotics Mir500 Firmware All All All All
Hardware Enabled-robotics Er-flex - All All All
Hardware Enabled-robotics Er-flex - All All All
Operating System Enabled-robotics Er-flex Firmware All All All All
Hardware Enabled-robotics Er-lite - All All All
Hardware Enabled-robotics Er-lite - All All All
Operating System Enabled-robotics Er-lite Firmware All All All All
Hardware Enabled-robotics Er-one - All All All
Hardware Enabled-robotics Er-one - All All All
Operating System Enabled-robotics Er-one Firmware All All All All
Hardware Mobile-industrial-robotics Er200 - All All All
Hardware Mobile-industrial-robotics Er200 - All All All
Operating System Mobile-industrial-robotics Er200 Firmware All All All All
Hardware Uvd-robots Uvd Robots - All All All
Hardware Uvd-robots Uvd Robots - All All All
Operating System Uvd-robots Uvd Robots Firmware All All All All

References

ReferenceSourceLinkTags
RVD#2555: MiR ROS computational graph is exposed to all network interfaces, including poorly secured wireless networks and open wired ones · Issue #2555 · aliasrobotics/RVD · GitHub CONFIRM github.com Exploit, Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

LEGACY: Víctor Mayoral Vilches, Alfonso Glera, Lander Usategui, Unai Ayucar, Xabier Sáez de Cámara (Alias Robotics)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report