PT-2020-12025 · Unknown · Safety Plc
Bernhard Dieber
+1
·
Published
2020-06-24
·
Updated
2020-07-06
·
CVE-2020-10276
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Safety PLC (affected versions not specified)
Description
The password for the safety PLC is the default and easily accessible, allowing a manipulated program to be uploaded, which can disable the emergency stop when an object is too close to the robot. This issue does not affect navigation or components dependent on the laser scanner, making it difficult to detect before an incident occurs. However, the laser scanner configuration can also be affected, further altering the safety of the device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Safety Plc