Vulnerability Details CVE-2020-10275
The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-10275
-
cpe:2.3:h:easyrobotics:er-flex:-
-
cpe:2.3:h:easyrobotics:er-lite:-
-
cpe:2.3:h:easyrobotics:er-one:-
-
cpe:2.3:h:easyrobotics:er200:-
-
cpe:2.3:h:mobile-industrial-robots:mir1000:-
-
cpe:2.3:h:mobile-industrial-robots:mir100:-
-
cpe:2.3:h:mobile-industrial-robots:mir200:-
-
cpe:2.3:h:mobile-industrial-robots:mir250:-
-
cpe:2.3:h:mobile-industrial-robots:mir500:-
-
cpe:2.3:h:uvd-robots:uvd:-
-
cpe:2.3:o:easyrobotics:er-flex_firmware:-
-
cpe:2.3:o:easyrobotics:er-lite_firmware:-
-
cpe:2.3:o:easyrobotics:er-one_firmware:-
-
cpe:2.3:o:easyrobotics:er200_firmware:-
-
cpe:2.3:o:mobile-industrial-robots:mir1000_firmware:-
-
cpe:2.3:o:mobile-industrial-robots:mir100_firmware:*
-
cpe:2.3:o:mobile-industrial-robots:mir200_firmware:-
-
cpe:2.3:o:mobile-industrial-robots:mir250_firmware:-
-
cpe:2.3:o:mobile-industrial-robots:mir500_firmware:-
-
cpe:2.3:o:uvd-robots:uvd_firmware:-