CVE-2020-10290 - CVE House
Back to Database
Status published Medium CVE-2020-10290

RVD#1495: Universal Robots URCaps execute with unbounded privileges

Vulnerability Description

Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-10290

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Victor Mayoral Vilches and Unai Ayucar Carbajo (Alias Robotics)

Affected Vendor

Universal Robots

View all reports →

Affected Software

URx
Vulnerable Versions:
unspecified

Timeline

Official Publish: August 21st, 2020
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)