CVE-2020-10272: RVD#2554: MiR ROS computational graph presents no authentication mechanisms
MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and CVE-2020-10271, this flaw allows malicious actors to command the robot at desire.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10272?
CVE-2020-10272 is a vulnerability that allows attackers with access to the internal wireless and wired networks to take control of the MiR robots, such as MiR100 and MiR200, by exploiting the lack of authentication in the Robot Operating System (ROS) default packages.
How severe is CVE-2020-10272?
CVE-2020-10272 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
Which MiR robots are affected by CVE-2020-10272?
MiR100, MiR200, MiR250, MiR500, and MiR1000 robots are affected by CVE-2020-10272.
How can an attacker exploit CVE-2020-10272?
An attacker can exploit CVE-2020-10272 by gaining access to the internal wireless and wired networks of the MiR robots and taking control of them.
Is there a fix for CVE-2020-10272?
At the moment, there is no known fix or patch for CVE-2020-10272. It is recommended to follow the guidance provided by the vendor or manufacturer of the affected MiR robots.