CVE-2020-10288: RVD#3327: No authentication required for accesing ABB IRC5 FTP server
Published Jul 15, 2020
·Updated
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.
Affected Software
4 affected components
ABB Robotware=5.09
ABB Irb140
ABB IRC5
Windriver Vxworks=5.5.1
Event History
Jul 15, 2020
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-10288?
CVE-2020-10288 is a vulnerability in IRC5 that exposes an ftp server (port 21) and accepts any input for username and password.
2
How severe is CVE-2020-10288?
CVE-2020-10288 is classified as critical with a severity score of 9.8.
3
What software is affected by CVE-2020-10288?
Abb Robotware version 5.09 is affected by CVE-2020-10288.
4
How can I fix CVE-2020-10288?
Currently, there is no known fix for CVE-2020-10288. It is recommended to monitor for vendor patches or security advisories.
5
Where can I find more information about CVE-2020-10288?
You can find more information about CVE-2020-10288 at the following reference link: [GitHub Issue](https://github.com/aliasrobotics/RVD/issues/3327)