CVE-2020-10286
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
15/07/2020
Last modified:
21/12/2021
Description
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ufactory:xarm_5_lite_firmware:*:*:*:*:*:*:*:* | 1.5.0 (including) | |
| cpe:2.3:h:ufactory:xarm_5_lite:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ufactory:xarm_6_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ufactory:xarm_6:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ufactory:xarm_7_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ufactory:xarm_7:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



