Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10290

Опубликовано: 21 авг. 2020
Источник: nvd
CVSS3: 6.8
CVSS3: 6.8
CVSS2: 7.2
EPSS Низкий

Описание

Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:sintef:urx:-:*:*:*:*:*:*:*

EPSS

Процентиль: 11%
0.00036
Низкий

6.8 Medium

CVSS3

6.8 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-250
CWE-269

Связанные уязвимости

github
больше 3 лет назад

Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system

EPSS

Процентиль: 11%
0.00036
Низкий

6.8 Medium

CVSS3

6.8 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-250
CWE-269