PT-2020-12025 · Unknown · Safety Plc

Bernhard Dieber

+1

·

Published

2020-06-24

·

Updated

2020-07-06

·

CVE-2020-10276

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Safety PLC (affected versions not specified)
Description The password for the safety PLC is the default and easily accessible, allowing a manipulated program to be uploaded, which can disable the emergency stop when an object is too close to the robot. This issue does not affect navigation or components dependent on the laser scanner, making it difficult to detect before an incident occurs. However, the laser scanner configuration can also be affected, further altering the safety of the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10276

Affected Products

Safety Plc