CVE-2020-10278: RVD#2561: Unprotected BIOS allows user to boot from live OS image.
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10278?
The severity of CVE-2020-10278 is medium with a severity value of 4.6.
How does CVE-2020-10278 impact MiR's Computer?
CVE-2020-10278 allows a Bad Operator to modify settings such as boot order on MiR's Computer by exploiting the unprotected BIOS onboard.
Which software versions are affected by CVE-2020-10278?
Aliasrobotics Mir100, Mir200, Mir250, Mir500, Mir1000, Mobile-industrial-robotics Er200, Enabled-robotics Er-lite, Er-flex, Er-one, and Uvd-robots Uvd Robots firmware versions up to and including 2.8.1.1 are affected by CVE-2020-10278.
Is Aliasrobotics Mir100, Mir200, Mir250, Mir500, Mir1000, Mobile-industrial-robotics Er200, Enabled-robotics Er-lite, Er-flex, Er-one, or Uvd-robots Uvd Robots software vulnerable to CVE-2020-10278?
No, Aliasrobotics Mir100, Mir200, Mir250, Mir500, Mir1000, Mobile-industrial-robotics Er200, Enabled-robotics Er-lite, Er-flex, Er-one, and Uvd-robots Uvd Robots software are not vulnerable to CVE-2020-10278.
How can I fix the vulnerability CVE-2020-10278?
To fix CVE-2020-10278, it is recommended to protect the BIOS onboard MiR's Computer by setting a password to prevent unauthorized modification of settings.