CVE-2020-10269
Last modified
CVE-2020-10269 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode. Credentials to such wireless Access Point default to well known and widely spread SSID (MiR_RXXXX) and passwords (omitted). EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode. Credentials to such wireless Access Point default to well known and widely spread SSID (MiR_RXXXX) and passwords (omitted). This information is also available in past User Guides and manuals which the vendor distributed. We have confirmed this flaw in MiR100 and MiR200 but it might also apply to MiR250, MiR500 and MiR1000.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Aliasrobotics | Mir100 Firmware | <= 2.8.1.1 |
| Aliasrobotics | Mir200 Firmware | <= 2.8.1.1 |
| Aliasrobotics | Mir250 Firmware | <= 2.8.1.1 |
| Aliasrobotics | Mir500 Firmware | <= 2.8.1.1 |
| Aliasrobotics | Mir1000 Firmware | <= 2.8.1.1 |
| Mobile-Industrial-Robotics | Er200 Firmware | <= 2.8.1.1 |
| Enabled-Robotics | Er-Lite Firmware | <= 2.8.1.1 |
| Enabled-Robotics | Er-Flex Firmware | <= 2.8.1.1 |
| Enabled-Robotics | Er-One Firmware | <= 2.8.1.1 |
| Uvd-Robots | Uvd Robots Firmware | <= 2.8.1.1 |
References
- https://github.com/aliasrobotics/RVD/issues/2566Third Party Advisory
- https://github.com/aliasrobotics/RVD/issues/2566Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10269?
How severe is CVE-2020-10269?
How do I fix CVE-2020-10269?
Are you affected by CVE-2020-10269?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
