Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Alias

Published:

Updated: 2024-09-16T19:15:10.454Z

Reserved: 2020-03-10T00:00:00

Link: CVE-2020-10290

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-08-21T15:15:12.540

Modified: 2024-11-21T04:55:09.053

Link: CVE-2020-10290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.