Vulnerability Details CVE-2020-10286
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.9%
CVSS Severity
CVSS v3 Score 9.4
CVSS v2 Score 5.8
Products affected by CVE-2020-10286
-
cpe:2.3:h:ufactory:xarm_5_lite:-
-
cpe:2.3:h:ufactory:xarm_6:-
-
cpe:2.3:h:ufactory:xarm_7:-
-
cpe:2.3:o:ufactory:xarm_5_lite_firmware:-
-
cpe:2.3:o:ufactory:xarm_5_lite_firmware:1.5.0
-
cpe:2.3:o:ufactory:xarm_6_firmware:-
-
cpe:2.3:o:ufactory:xarm_7_firmware:-