CVE-2020-10286
Last modified
CVE-2020-10286 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ufactory | Xarm 5 Lite Firmware | <= 1.5.0 |
| Ufactory | Xarm 6 Firmware | All versions |
| Ufactory | Xarm 7 Firmware | All versions |
References
- https://github.com/aliasrobotics/RVD/issues/3323Third Party Advisory
- https://github.com/aliasrobotics/RVD/issues/3323Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10286?
How severe is CVE-2020-10286?
How do I fix CVE-2020-10286?
Are you affected by CVE-2020-10286?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
