CVE-2020-10273: RVD#2560: Unprotected intellectual property in Mobile Industrial Robots (MiR) controllers
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property and data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10273?
The severity of CVE-2020-10273 is high with a severity value of 7.5.
Which firmware versions are affected by CVE-2020-10273?
Firmware versions 2.8.1.1 and before are affected by CVE-2020-10273.
How do I protect against CVE-2020-10273?
To protect against CVE-2020-10273, update the firmware to a version after 2.8.1.1 that includes the necessary encryption and protection for intellectual property artifacts.
Can attackers retrieve intellectual property artifacts installed in the robots?
Yes, attackers with access to the robot or the robot network can retrieve intellectual property artifacts installed in the robots.
Is encryption used to protect intellectual property artifacts in MiR controllers?
No, MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect intellectual property artifacts.