Vulnerability Description
There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mobile-Industrial-Robots | Mir100 Firmware | <= 2.8.1.1 |
| Mobile-Industrial-Robots | Mir100 | - |
| Mobile-Industrial-Robots | Mir200 Firmware | - |
| Mobile-Industrial-Robots | Mir200 | - |
| Mobile-Industrial-Robots | Mir250 Firmware | - |
| Mobile-Industrial-Robots | Mir250 | - |
| Mobile-Industrial-Robots | Mir500 Firmware | - |
| Mobile-Industrial-Robots | Mir500 | - |
| Mobile-Industrial-Robots | Mir1000 Firmware | - |
| Mobile-Industrial-Robots | Mir1000 | - |
| Easyrobotics | Er200 Firmware | - |
| Easyrobotics | Er200 | - |
| Easyrobotics | Er-Lite Firmware | - |
| Easyrobotics | Er-Lite | - |
| Easyrobotics | Er-Flex Firmware | - |
| Easyrobotics | Er-Flex | - |
| Easyrobotics | Er-One Firmware | - |
| Easyrobotics | Er-One | - |
| Uvd-Robots | Uvd Firmware | - |
| Uvd-Robots | Uvd | - |
Related Weaknesses (CWE)
References
- https://github.com/aliasrobotics/RVD/issues/2562Third Party Advisory
- https://github.com/aliasrobotics/RVD/issues/2562Third Party Advisory
FAQ
What is CVE-2020-10277?
CVE-2020-10277 is a vulnerability with a CVSS score of 6.4 (MEDIUM). There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually addin...
How severe is CVE-2020-10277?
CVE-2020-10277 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10277?
Check the references section above for vendor advisories and patch information. Affected products include: Mobile-Industrial-Robots Mir100 Firmware, Mobile-Industrial-Robots Mir100, Mobile-Industrial-Robots Mir200 Firmware, Mobile-Industrial-Robots Mir200, Mobile-Industrial-Robots Mir250 Firmware.