PT-2020-12020 · Open Robotics+1 · Ros+2
Alfonso Glera
+4
·
Published
2020-06-24
·
Updated
2020-07-06
·
CVE-2020-10271
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MiR100, MiR200 and other MiR robots (affected versions not specified)
Description
The issue is related to the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces. This exposure is due to a bad setup and can be exploited by malicious operators to take control of the ROS logic and, consequently, the complete robot. The ROS computational graph can be accessed fully from the wired exposed ports. In combination with other flaws, the computational graph can also be fetched and interacted with from wireless networks.
Recommendations
For MiR100, MiR200 and other MiR robots, appropriately configure ROS to mitigate the issue.
Apply custom patches as appropriate to secure the ROS computational graph.
Restrict access to the wired exposed ports to minimize the risk of exploitation.
Consider disabling unnecessary network interfaces to reduce the attack surface until a proper configuration or patch is applied.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mir100
Mir200
Ros