PT-2020-12016 · Universal Robots · Universal Robots Control Box Cb 3.1+3

Víctor Mayoral Vilches

·

Published

2020-04-06

·

Updated

2021-12-20

·

CVE-2020-10267

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Universal Robots control box CB 3.1 versions 1.10 through 1.12.1
Description The issue concerns the lack of encryption or protection for intellectual property artifacts installed from the UR+ platform, specifically URCaps files. These files, stored as plain zip files under '/root/.urcaps', contain logic to add functionality to UR3, UR5, and UR10 robots. An attacker with access to the robot or its network could exploit this, in combination with other flaws, to retrieve and exfiltrate installed intellectual property.
Recommendations For Universal Robots control box CB 3.1 versions 1.10 through 1.12.1, consider restricting access to the '/root/.urcaps' directory to minimize the risk of exploitation. As a temporary workaround, limit network access to the robot to reduce the potential for attackers to retrieve URCaps files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Encryption of Sensitive Data

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10267

Affected Products

Ur10
Ur3
Ur5
Universal Robots Control Box Cb 3.1