CVE-2020-10265

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
06/04/2020
Last modified:
06/04/2020

Description

Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starting/stopping programs, shutdown, reset safety and more. The DashBoard server is not protected by any kind of authentication or authorization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:universal-robots:ur_software:*:*:*:*:*:*:*:* 3.0.14989 (including) 3.3.3.292 (including)
cpe:2.3:h:universal-robots:ur10:-:*:*:*:*:*:*:*
cpe:2.3:h:universal-robots:ur3:-:*:*:*:*:*:*:*
cpe:2.3:h:universal-robots:ur5:-:*:*:*:*:*:*:*
cpe:2.3:a:universal-robots:ur_software:*:*:*:*:*:*:*:* 1.4 (including)
cpe:2.3:h:universal-robots:ur10:-:*:*:*:*:*:*:*
cpe:2.3:h:universal-robots:ur5:-:*:*:*:*:*:*:*
cpe:2.3:a:universal-robots:ur_software:*:*:*:*:*:*:*:* 5.0 (including)
cpe:2.3:h:universal-robots:ur10e:-:*:*:*:*:*:*:*
cpe:2.3:h:universal-robots:ur3e:-:*:*:*:*:*:*:*
cpe:2.3:h:universal-robots:ur5e:-:*:*:*:*:*:*:*