CVE-2020-10277: RVD#2562: Booting from a live image leads to exfiltration of sensible information and privilege escalation
Published Jun 24, 2020
·Updated
There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.
Affected Software
20 affected components
Mobile-industrial-robots Mir100 Firmware<=2.8.1.1
Mobile-industrial-robots Mir100
Mobile-industrial-robots Mir200 Firmware
Mobile-industrial-robots Mir200
Mobile-industrial-robots Mir250 Firmware
Mobile-industrial-robots Mir250
Mobile-industrial-robots Mir500 Firmware
Mobile-industrial-robots Mir500
Mobile-industrial-robots Mir1000 Firmware
Mobile-industrial-robots Mir1000
Easyrobotics Er200 Firmware
Easyrobotics Er200
Easyrobotics Er-lite Firmware
Easyrobotics Er-lite
Easyrobotics Er-flex Firmware
Easyrobotics Er-flex
Easyrobotics Er-one Firmware
Easyrobotics Er-one
Uvd-robots Uvd Firmware
Uvd-robots Uvd
Event History
Jun 24, 2020
CVE Published
via MITRE·04:55 AM
Data Sourced
via MITRE·04:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-10277?
The severity of CVE-2020-10277 is medium (6.4).
2
How can a bad operator exploit CVE-2020-10277?
A bad operator can exploit CVE-2020-10277 by booting from a live OS image and extracting sensitive files or escalating privileges.
3
Which software versions are affected by CVE-2020-10277?
The Mobile-industrial-robots Mir100 Firmware version up to and including 2.8.1.1 is affected by CVE-2020-10277.
4
How can I prevent exploitation of CVE-2020-10277?
To prevent exploitation of CVE-2020-10277, implement a mechanism to prevent booting from a live OS image and restrict access to sensitive files.
5
Is Easyrobotics Er200 firmware vulnerable to CVE-2020-10277?
No, Easyrobotics Er200 firmware is not vulnerable to CVE-2020-10277.