ID

VAR-202004-0391


CVE

CVE-2020-10264


TITLE

Universal Robots Robot Controllers Vulnerability regarding information leakage in

Trust: 0.8

sources: JVNDB: JVNDB-2020-003777

DESCRIPTION

CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Data Exchange) interface on port 30004 which allows setting registers, the speed slider fraction as well as digital and analog Outputs. Additionally unautheticated reading of robot data is also possible. Universal Robots Robot Controllers There is an information leakage vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state

Trust: 1.62

sources: NVD: CVE-2020-10264 // JVNDB: JVNDB-2020-003777

IOT TAXONOMY

category:['industrial device']sub_category:robot

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:universal robotsmodel:ur softwarescope:gteversion:3.0.14989

Trust: 1.0

vendor:universal robotsmodel:ur softwarescope:gteversion:5.0

Trust: 1.0

vendor:universal robotsmodel:ur softwarescope:lteversion:3.3.3.292

Trust: 1.0

vendor:universal robotsmodel:ur softwarescope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-003777 // NVD: CVE-2020-10264

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-10264
value: HIGH

Trust: 1.0

cve@aliasrobotics.com: CVE-2020-10264
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-003777
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202004-143
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-10264
severity: MEDIUM
baseScore: 5.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 6.5
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-003777
severity: MEDIUM
baseScore: 5.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:P
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-10264
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 2.0

NVD: JVNDB-2020-003777
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-003777 // CNNVD: CNNVD-202004-143 // NVD: CVE-2020-10264 // NVD: CVE-2020-10264

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

problemtype:CWE-306

Trust: 1.0

sources: JVNDB: JVNDB-2020-003777 // NVD: CVE-2020-10264

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202004-143

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-202004-143

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-003777

PATCH

title:Real-Time Data Exchange (RTDE) Guideurl:https://www.universal-robots.com/articles/ur-articles/real-time-data-exchange-rtde-guide/

Trust: 0.8

sources: JVNDB: JVNDB-2020-003777

EXTERNAL IDS

db:NVDid:CVE-2020-10264

Trust: 2.5

db:JVNDBid:JVNDB-2020-003777

Trust: 0.8

db:CNNVDid:CNNVD-202004-143

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2020-003777 // CNNVD: CNNVD-202004-143 // NVD: CVE-2020-10264

REFERENCES

url:https://www.universal-robots.com/how-tos-and-faqs/how-to/ur-how-tos/real-time-data-exchange-rtde-guide/

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-10264

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-10264

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2020-003777 // CNNVD: CNNVD-202004-143 // NVD: CVE-2020-10264

SOURCES

db:OTHERid: -
db:JVNDBid:JVNDB-2020-003777
db:CNNVDid:CNNVD-202004-143
db:NVDid:CVE-2020-10264

LAST UPDATE DATE

2025-01-30T20:28:50.211000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-003777date:2020-04-24T00:00:00
db:CNNVDid:CNNVD-202004-143date:2021-09-15T00:00:00
db:NVDid:CVE-2020-10264date:2024-11-21T04:55:05.597

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-003777date:2020-04-24T00:00:00
db:CNNVDid:CNNVD-202004-143date:2020-04-06T00:00:00
db:NVDid:CVE-2020-10264date:2020-04-06T12:15:12.707