9.4
CVE-2020-10286
- EPSS 0.74%
- Veröffentlicht 15.07.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:08
- Quelle cve@aliasrobotics.com
- CVE-Watchlists
- Unerledigt
RVD#3323: Mismanaged permission implementation leads to privilege escalation, exfiltration of sensitive information, and DoS
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ufactory ≫ Xarm 5 Lite Firmware Version <= 1.5.0
Ufactory ≫ Xarm 6 Firmware Version-
Ufactory ≫ Xarm 7 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.74% | 0.499 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5.8 | 6.5 | 6.4 |
AV:A/AC:L/Au:N/C:P/I:P/A:P
|
| cve@aliasrobotics.com | 9.4 | 3.9 | 5.5 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-656 Reliance on Security Through Obscurity
The product uses a protection mechanism whose strength depends heavily on its obscurity, such that knowledge of its algorithms or key data is sufficient to defeat the mechanism.
https://github.com/aliasrobotics/RVD/issues/3323