Vulnerability Description
Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sintef | Urx | - |
Related Weaknesses (CWE)
References
- https://github.com/aliasrobotics/RVD/issues/1495Issue TrackingThird Party Advisory
- https://github.com/aliasrobotics/RVD/issues/1495Issue TrackingThird Party Advisory
FAQ
What is CVE-2020-10290?
CVE-2020-10290 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the ove...
How severe is CVE-2020-10290?
CVE-2020-10290 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10290?
Check the references section above for vendor advisories and patch information. Affected products include: Sintef Urx.