Description
The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in combination with CVE-2020-10273 allows any attacker connected to the robot networks (wired or wireless) to exfiltrate all stored data (e.g. indoor mapping images) and associated metadata from the robot's database.
Published: 2020-06-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-2729 The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in combination with CVE-2020-10273 allows any attacker connected to the robot networks (wired or wireless) to exfiltrate all stored data (e.g. indoor mapping images) and associated metadata from the robot's database.
History

No history.

Subscriptions

Easyrobotics Er-flex Er-flex Firmware Er-lite Er-lite Firmware Er-one Er-one Firmware Er200 Er200 Firmware
Mobile-industrial-robots Mir100 Mir1000 Mir1000 Firmware Mir100 Firmware Mir200 Mir200 Firmware Mir250 Mir250 Firmware Mir500 Mir500 Firmware
Uvd-robots Uvd Uvd Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Alias

Published:

Updated: 2024-09-17T00:05:33.397Z

Reserved: 2020-03-10T00:00:00.000Z

Link: CVE-2020-10274

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-24T05:15:13.113

Modified: 2024-11-21T04:55:06.977

Link: CVE-2020-10274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses