RVD#1495: Universal Robots URCaps execute with unbounded privileges
Vulnerability Description
Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-10290
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Victor Mayoral Vilches and Unai Ayucar Carbajo (Alias Robotics)
More from Universal Robots
View All →Affected Vendor
Universal Robots
View all reports →