PT-2020-12028 · Canonical+1 · Ubuntu+1
Victor Mayoral Vilches
·
Published
2020-06-24
·
Updated
2022-04-25
·
CVE-2020-10279
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
MiR robot controllers (central computation unit) version Ubuntu 16.04.2
Description
The MiR robot controllers' central computation unit uses Ubuntu 16.04.2, an operating system initially designed for desktop use, which presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were granted via file creation, access race conditions, insecure home directory configurations, and defaults that facilitate Denial of Service (DoS) attacks.
Recommendations
For Ubuntu 16.04.2, consider updating to a newer version of the operating system to address the insecure defaults. As a temporary workaround, restrict access to sensitive files and directories to minimize the risk of access escalation and Denial of Service (DoS) attacks. Additionally, review and secure home directory configurations to prevent unauthorized access.
Fix
Race Condition
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mir Robot Controllers
Ubuntu