CVE-2023-3103: Authentication Bypass by Spoofing in Unitree Robotics A1
Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream. In addition, if a MITM attack is carried out, it is possible to consume the robot's resources, which could lead to a denial-of-service (DOS) condition.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-3103?
CVE-2023-3103 is an authentication bypass vulnerability in Unitree Robotics A1, which allows a local attacker to perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream and consume its resources.
How can an attacker exploit CVE-2023-3103?
An attacker can exploit CVE-2023-3103 by bypassing the authentication mechanism of the Unitree Robotics A1 and perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream.
How can I check if my Unitree Robotics A1 is affected by CVE-2023-3103?
To check if your Unitree Robotics A1 is affected by CVE-2023-3103, verify the firmware version of your device and ensure it is not using the vulnerable firmware version.
What is the severity of CVE-2023-3103?
CVE-2023-3103 has a severity rating of high (8) due to the potential for a local attacker to perform a Man-in-the-Middle (MITM) attack on the camera video stream and consume the robot's resources.
How do I mitigate CVE-2023-3103?
To mitigate CVE-2023-3103, update the firmware of your Unitree Robotics A1 to a version that is not vulnerable to the authentication bypass vulnerability.