PT-2020-12020 · Open Robotics+1 · Ros+2

Alfonso Glera

+4

·

Published

2020-06-24

·

Updated

2020-07-06

·

CVE-2020-10271

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MiR100, MiR200 and other MiR robots (affected versions not specified)
Description The issue is related to the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces. This exposure is due to a bad setup and can be exploited by malicious operators to take control of the ROS logic and, consequently, the complete robot. The ROS computational graph can be accessed fully from the wired exposed ports. In combination with other flaws, the computational graph can also be fetched and interacted with from wireless networks.
Recommendations For MiR100, MiR200 and other MiR robots, appropriately configure ROS to mitigate the issue. Apply custom patches as appropriate to secure the ROS computational graph. Restrict access to the wired exposed ports to minimize the risk of exploitation. Consider disabling unnecessary network interfaces to reduce the attack surface until a proper configuration or patch is applied.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10271

Affected Products

Mir100
Mir200
Ros