Easyrobotics
Easyrobotics Er-flex Firmware: vulnerabilidades y CVE
Easyrobotics Er-flex Firmware tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-10280 | Alta (7.5) | 1.2% | — | 24 jun 2020 | The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively blocking the access to the dashboard. |
| CVE-2020-10277 | Media (6.4) | 0.38% | — | 24 jun 2020 | There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with… |
| CVE-2020-10276 | Crítica (9.8) | 1.5% | — | 24 jun 2020 | The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is… |
| CVE-2020-10275 | Crítica (9.8) | 0.96% | — | 24 jun 2020 | The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with… |
| CVE-2020-10274 | Alta (7.1) | 0.90% | — | 24 jun 2020 | The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in… |