CVE-2020-10273

HIGHCVSS 7.5/10EPSS 0.86%

Last modified

CVE-2020-10273 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.. EPSS estimates a 0.86% chance of exploitation in the next 30 days.

Description

MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.86%

53.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AliasroboticsMir100 Firmware<= 2.8.1.1
AliasroboticsMir200 Firmware<= 2.8.1.1
AliasroboticsMir250 Firmware<= 2.8.1.1
AliasroboticsMir500 Firmware<= 2.8.1.1
AliasroboticsMir1000 Firmware<= 2.8.1.1
Mobile-Industrial-RoboticsEr200 Firmware<= 2.8.1.1
Enabled-RoboticsEr-Lite Firmware<= 2.8.1.1
Enabled-RoboticsEr-Flex Firmware<= 2.8.1.1
Enabled-RoboticsEr-One Firmware<= 2.8.1.1
Uvd-RobotsUvd Robots Firmware<= 2.8.1.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-10273?
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.
How severe is CVE-2020-10273?
CVE-2020-10273 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.86% probability of exploitation in the next 30 days.
How do I fix CVE-2020-10273?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-10273?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST