CVE-2020-10272 Details
Description
MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and CVE-2020-10271, this flaw allows malicious actors to command the robot at desire.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aliasrobotics/RVD/issues/2554 | CVE | ExploitThird Party Advisory |
| https://github.com/aliasrobotics/RVD/issues/2554 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aliasrobotics mir100 firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| aliasrobotics mir100 | All versions |
CPE
Remediation
| |
| aliasrobotics mir200 firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| aliasrobotics mir200 | All versions |
CPE
Remediation
| |
| aliasrobotics mir250 firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| aliasrobotics mir250 | All versions |
CPE
Remediation
| |
| aliasrobotics mir500 firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| aliasrobotics mir500 | All versions |
CPE
Remediation
| |
| aliasrobotics mir1000 firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| aliasrobotics mir1000 | All versions |
CPE
Remediation
| |
| mobile-industrial-robotics er200 firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| mobile-industrial-robotics er200 | All versions |
CPE
Remediation
| |
| enabled-robotics er-lite firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| enabled-robotics er-lite | All versions |
CPE
Remediation
| |
| enabled-robotics er-flex firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| enabled-robotics er-flex | All versions |
CPE
Remediation
| |
| enabled-robotics er-one firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| enabled-robotics er-one | All versions |
CPE
Remediation
| |
| uvd-robots uvd robots firmware | <= 2.8.1.1 |
CPE
Remediation
| |
| uvd-robots uvd robots | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 6, 2020 | Initial Analysis | [email protected] |