CVE-2020-10280
Severity CVSS v4.0:
Pending analysis
Type:
CWE-404
Improper Resource Shutdown or Release
Publication date:
24/06/2020
Last modified:
02/07/2020
Description
The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively blocking the access to the dashboard.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mobile-industrial-robots:mir100_firmware:*:*:*:*:*:*:*:* | 2.8.1.1 (including) | |
| cpe:2.3:h:mobile-industrial-robots:mir100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mobile-industrial-robots:mir200_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mobile-industrial-robots:mir200:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mobile-industrial-robots:mir250_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mobile-industrial-robots:mir250:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mobile-industrial-robots:mir500_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mobile-industrial-robots:mir500:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mobile-industrial-robots:mir1000_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mobile-industrial-robots:mir1000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:easyrobotics:er200_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:easyrobotics:er200:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:easyrobotics:er-lite_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:easyrobotics:er-lite:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:easyrobotics:er-flex_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



