CVE-2020-10277

There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.
References
Link Resource
https://github.com/aliasrobotics/RVD/issues/2562 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mobile-industrial-robots:mir100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mobile-industrial-robots:mir100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mobile-industrial-robots:mir200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mobile-industrial-robots:mir200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mobile-industrial-robots:mir250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mobile-industrial-robots:mir250:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mobile-industrial-robots:mir500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mobile-industrial-robots:mir500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mobile-industrial-robots:mir1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mobile-industrial-robots:mir1000:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:easyrobotics:er200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:easyrobotics:er200:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:easyrobotics:er-lite_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:easyrobotics:er-lite:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:easyrobotics:er-flex_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:easyrobotics:er-flex:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:easyrobotics:er-one_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:easyrobotics:er-one:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:uvd-robots:uvd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:uvd-robots:uvd:-:*:*:*:*:*:*:*

History

14 Sep 2021, 17:20

Type Values Removed Values Added
CWE CWE-200 NVD-CWE-Other

Information

Published : 2020-06-24 05:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-10277

Mitre link : CVE-2020-10277

CVE.ORG link : CVE-2020-10277


JSON object : View

Products Affected

mobile-industrial-robots

  • mir250
  • mir250_firmware
  • mir1000_firmware
  • mir100
  • mir1000
  • mir200
  • mir100_firmware
  • mir500
  • mir200_firmware
  • mir500_firmware

easyrobotics

  • er200_firmware
  • er-one_firmware
  • er-lite_firmware
  • er-flex
  • er200
  • er-one
  • er-lite
  • er-flex_firmware

uvd-robots

  • uvd_firmware
  • uvd
CWE
NVD-CWE-Other CWE-656

Reliance on Security Through Obscurity