CVE-2020-10284
RVD#3321: No Authentication required to exert manual control of the robot
No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but as in xarm_studio 1.3.0 the option is missing from the menu. Assuming manual control, even by forcefully removing the current operator from an active session.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Produtos afetados
uFactory · xArm5 Lite, xArm 6 and xArm 7Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →