PT-2021-4027 · Kuka · Kuka Kr C4 Control

Chen Jie

·

Published

2021-07-28

·

Updated

2022-06-08

·

CVE-2021-33016

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KUKA KR C4 control software versions prior to 8.7 Any product running KSS (affected versions not specified)
Description The issue is related to hard-coded credentials in the system, allowing an attacker to gain full access, including read, write, and delete capabilities, to sensitive folders. This can be exploited by a remote attacker to gain full system access.
Recommendations For KUKA KR C4 control software versions prior to 8.7, update to version 8.7 or later to resolve the issue. For products running KSS, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04554
CVE-2021-33016

Affected Products

Kuka Kr C4 Control