Mobile-industrial-robots
Mobile-industrial-robots Mir1000 Firmware: vulnerabilities and CVEs
Mobile-industrial-robots Mir1000 Firmware has 5 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months0
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10280 | High (7.5) | 1.2% | — | Jun 24, 2020 | The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively blocking the access to the dashboard. |
| CVE-2020-10277 | Medium (6.4) | 0.38% | — | Jun 24, 2020 | There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with… |
| CVE-2020-10276 | Critical (9.8) | 1.5% | — | Jun 24, 2020 | The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is… |
| CVE-2020-10275 | Critical (9.8) | 0.96% | — | Jun 24, 2020 | The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with… |
| CVE-2020-10274 | High (7.1) | 0.90% | — | Jun 24, 2020 | The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in… |