Vulnerability Description
VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execute commands that are outside the scope of their privileges and within the scope of an admin account. If an attacker has access to VGo XAMPP Client credentials, they may be able to execute admin commands on the connected robot.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vecna | Vgo Firmware | 3.0.3.52164 |
| Vecna | Vgo | - |
Related Weaknesses (CWE)
References
- https://ics-cert.us-cert.gov/advisories/ICSA-18-114-01Third Party AdvisoryUS Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-18-114-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2018-17933?
CVE-2018-17933 is a vulnerability with a CVSS score of 8.8 (HIGH). VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execute commands that are outside the scope of their priv...
How severe is CVE-2018-17933?
CVE-2018-17933 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17933?
Check the references section above for vendor advisories and patch information. Affected products include: Vecna Vgo Firmware, Vecna Vgo.