PT-2021-4027 · Kuka · Kuka Kr C4 Control
Chen Jie
·
Published
2021-07-28
·
Updated
2022-06-08
·
CVE-2021-33016
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
KUKA KR C4 control software versions prior to 8.7
Any product running KSS (affected versions not specified)
Description
The issue is related to hard-coded credentials in the system, allowing an attacker to gain full access, including read, write, and delete capabilities, to sensitive folders. This can be exploited by a remote attacker to gain full system access.
Recommendations
For KUKA KR C4 control software versions prior to 8.7, update to version 8.7 or later to resolve the issue.
For products running KSS, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kuka Kr C4 Control