CVE-2020-10280: RVD#2568: Apache server is vulnerable to a DoS
Published Jun 24, 2020
·Updated
The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively blocking the access to the dashboard.
Affected Software
20 affected components
Mobile-industrial-robots Mir100 Firmware<=2.8.1.1
Mobile-industrial-robots Mir100
Mobile-industrial-robots Mir200 Firmware
Mobile-industrial-robots Mir200
Mobile-industrial-robots Mir250 Firmware
Mobile-industrial-robots Mir250
Mobile-industrial-robots Mir500 Firmware
Mobile-industrial-robots Mir500
Mobile-industrial-robots Mir1000 Firmware
Mobile-industrial-robots Mir1000
Easyrobotics Er200 Firmware
Easyrobotics Er200
Easyrobotics Er-lite Firmware
Easyrobotics Er-lite
Easyrobotics Er-flex Firmware
Easyrobotics Er-flex
Easyrobotics Er-one Firmware
Easyrobotics Er-one
Uvd-robots Uvd Firmware
Uvd-robots Uvd
Event History
Jun 24, 2020
CVE Published
via MITRE·05:45 AM
Data Sourced
via MITRE·05:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-10280?
CVE-2020-10280 is a vulnerability in the Apache server on port 80 that host the web interface, allowing for a denial of service (DoS) attack by spamming incomplete HTTP headers.
2
What software is affected by CVE-2020-10280?
The vulnerability affects the Mobile-industrial-robots Mir100 Firmware version up to and including 2.8.1.1.
3
How severe is CVE-2020-10280?
CVE-2020-10280 has a severity rating of 7.5 (High).
4
How can the CVE-2020-10280 vulnerability be exploited?
The vulnerability can be exploited by spamming incomplete HTTP headers, effectively blocking access to the dashboard.
5
Is there a solution for CVE-2020-10280?
At this time, there is no known solution for CVE-2020-10280.