ZeroHour

CVE-2020-10286

CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
Description

the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.

Vendors
ufactory
Products
xarm 5 lite firmware, xarm 6 firmware, xarm 7 firmware
Weakness
CWE-656, CWE-269
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.