MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes,
allowing low-privilege users to create notes which are intended only for administrative users.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-28828 MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowing low-privilege users to create notes which are intended only for administrative users.
Fixes

Solution

Update to the newest software version, at least version 3.0.0


Workaround

If you cannot immediately update to the recommended version, we recommend the following compensating measures: 1. Operate the MiR system in a segmented and secured network with strict firewall rules 2. Secure user accounts on the MiR system as recommended in the MiR Cybersecurity Guide

History

Thu, 21 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Mobile-industrial-robots
Mobile-industrial-robots mir100
Mobile-industrial-robots mir1000
Mobile-industrial-robots mir200
Mobile-industrial-robots mir250
Mobile-industrial-robots mir500
Vendors & Products Mobile-industrial-robots
Mobile-industrial-robots mir100
Mobile-industrial-robots mir1000
Mobile-industrial-robots mir200
Mobile-industrial-robots mir250
Mobile-industrial-robots mir500

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:30:00 +0000

Type Values Removed Values Added
Description MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowing low-privilege users to create notes which are intended only for administrative users.
Title Insufficient authorization when creating notes
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TRO

Published:

Updated: 2025-08-20T15:23:37.679Z

Reserved: 2025-08-20T08:15:31.511Z

Link: CVE-2025-9228

cve-icon Vulnrichment

Updated: 2025-08-20T15:23:34.416Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-20T09:15:28.953

Modified: 2025-08-20T14:39:07.860

Link: CVE-2025-9228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-21T12:59:05Z