Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78r6-6wpw-grwr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system

Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system

EPSS

Процентиль: 11%
0.00036
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.8
nvd
больше 5 лет назад

Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system

EPSS

Процентиль: 11%
0.00036
Низкий

Дефекты

CWE-269