ZeroHour

CVE-2020-10284

CVSS 3.1
9.1 critical
EPSS
1%p71
Published
()
Modified
Description

No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but as in xarm_studio 1.3.0 the option is missing from the menu. Assuming manual control, even by forcefully removing the current operator from an active session.

Vendors
ufactory
Products
xarm studio
Weakness
CWE-656
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.