HIGH · 8.8

CVE-2020-10286

the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible file...

Vulnerability Description

the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
UfactoryXarm 5 Lite Firmware<= 1.5.0
UfactoryXarm 5 Lite-
UfactoryXarm 6 Firmware-
UfactoryXarm 6-
UfactoryXarm 7 Firmware-
UfactoryXarm 7-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-10286?

CVE-2020-10286 is a vulnerability with a CVSS score of 8.8 (HIGH). the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible file...

How severe is CVE-2020-10286?

CVE-2020-10286 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-10286?

Check the references section above for vendor advisories and patch information. Affected products include: Ufactory Xarm 5 Lite Firmware, Ufactory Xarm 5 Lite, Ufactory Xarm 6 Firmware, Ufactory Xarm 6, Ufactory Xarm 7 Firmware.