CVE-2020-10276: RVD#2558: Default credentials on SICK PLC allows disabling safety features
The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation and any other components dependent on the laser scanner are not affected (thus it is hard to detect before something happens) though the laser scanner configuration can also be affected altering further the safety of the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10276?
The severity of CVE-2020-10276 is critical with a severity value of 9.8.
What software versions are affected by CVE-2020-10276?
Mobile-industrial-robots Mir100 Firmware up to and including version 2.8.1.1 is affected by CVE-2020-10276.
How can an attacker exploit CVE-2020-10276?
An attacker can exploit CVE-2020-10276 by finding the default password for the safety PLC and uploading a manipulated program to disable the emergency stop.
Is Mobile-industrial-robots Mir200 affected by CVE-2020-10276?
Mobile-industrial-robots Mir200 is not affected by CVE-2020-10276.
Where can I find more information about CVE-2020-10276?
You can find more information about CVE-2020-10276 at the following link: [https://github.com/aliasrobotics/RVD/issues/2558](https://github.com/aliasrobotics/RVD/issues/2558)