CVE-2020-10276
Summary
| CVE | CVE-2020-10276 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-24 05:15:00 UTC |
| Updated | 2020-07-06 15:14:00 UTC |
| Description | The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation and any other components dependent on the laser scanner are not affected (thus it is hard to detect before something happens) though the laser scanner configuration can also be affected altering further the safety of the device. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Easyrobotics | Er-flex | - | All | All | All |
| Hardware | Easyrobotics | Er-flex | - | All | All | All |
| Operating System | Easyrobotics | Er-flex Firmware | - | All | All | All |
| Operating System | Easyrobotics | Er-flex Firmware | - | All | All | All |
| Hardware | Easyrobotics | Er-lite | - | All | All | All |
| Hardware | Easyrobotics | Er-lite | - | All | All | All |
| Operating System | Easyrobotics | Er-lite Firmware | - | All | All | All |
| Operating System | Easyrobotics | Er-lite Firmware | - | All | All | All |
| Hardware | Easyrobotics | Er-one | - | All | All | All |
| Hardware | Easyrobotics | Er-one | - | All | All | All |
| Operating System | Easyrobotics | Er-one Firmware | - | All | All | All |
| Operating System | Easyrobotics | Er-one Firmware | - | All | All | All |
| Hardware | Easyrobotics | Er200 | - | All | All | All |
| Hardware | Easyrobotics | Er200 | - | All | All | All |
| Operating System | Easyrobotics | Er200 Firmware | - | All | All | All |
| Operating System | Easyrobotics | Er200 Firmware | - | All | All | All |
| Hardware | Mobile-industrial-robots | Mir100 | - | All | All | All |
| Hardware | Mobile-industrial-robots | Mir100 | - | All | All | All |
| Hardware | Mobile-industrial-robots | Mir1000 | - | All | All | All |
| Hardware | Mobile-industrial-robots | Mir1000 | - | All | All | All |
| Operating System | Mobile-industrial-robots | Mir1000 Firmware | - | All | All | All |
| Operating System | Mobile-industrial-robots | Mir1000 Firmware | - | All | All | All |
| Operating System | Mobile-industrial-robots | Mir100 Firmware | All | All | All | All |
| Hardware | Mobile-industrial-robots | Mir200 | - | All | All | All |
| Hardware | Mobile-industrial-robots | Mir200 | - | All | All | All |
| Operating System | Mobile-industrial-robots | Mir200 Firmware | - | All | All | All |
| Operating System | Mobile-industrial-robots | Mir200 Firmware | - | All | All | All |
| Hardware | Mobile-industrial-robots | Mir250 | - | All | All | All |
| Hardware | Mobile-industrial-robots | Mir250 | - | All | All | All |
| Operating System | Mobile-industrial-robots | Mir250 Firmware | - | All | All | All |
| Operating System | Mobile-industrial-robots | Mir250 Firmware | - | All | All | All |
| Hardware | Mobile-industrial-robots | Mir500 | - | All | All | All |
| Hardware | Mobile-industrial-robots | Mir500 | - | All | All | All |
| Operating System | Mobile-industrial-robots | Mir500 Firmware | - | All | All | All |
| Operating System | Mobile-industrial-robots | Mir500 Firmware | - | All | All | All |
| Hardware | Uvd-robots | Uvd | - | All | All | All |
| Hardware | Uvd-robots | Uvd | - | All | All | All |
| Operating System | Uvd-robots | Uvd Firmware | - | All | All | All |
| Operating System | Uvd-robots | Uvd Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RVD#2558: Default credentials on SICK PLC allows disabling safety features · Issue #2558 · aliasrobotics/RVD · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Bernhard Dieber (Joanneum Research)
There are currently no legacy QID mappings associated with this CVE.