4.6
CVSSv2

CVE-2020-10277

Published: 24/06/2020 Updated: 14/09/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.4 | Impact Score: 5.5 | Exploitability Score: 0.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mobile-industrial-robots mir100 firmware

mobile-industrial-robots mir200 firmware -

mobile-industrial-robots mir250 firmware -

mobile-industrial-robots mir500 firmware -

mobile-industrial-robots mir1000 firmware -

easyrobotics er200 firmware -

easyrobotics er-lite firmware -

easyrobotics er-flex firmware -

easyrobotics er-one firmware -

uvd-robots uvd firmware -