Vulnerability Intelligence Report
RVD#1443: UR dashboard server enables unauthenticated remote control of core robot functions
CVE-2020-10265
Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starting/stopping programs, shutdown, reset safety and more. The DashBoard server is not protected by any kind of authentication or authorization.
No Active Exploit Signals
CVSS Base Score
9.4
CRITICAL
Exploitability:3.9
Impact Score:5.5
EPSS Probability:1.43%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-306 ↗CWE-306 (Missing Authentication for Critical Function)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Universal Robots | Universal Robots Robot Controllers CB 2, CB3, e-series | unspecified (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.430%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Alias Robotics S.L. · Vendor · Spain |
| Reserved | 2020-03-10T00:00:00 |
| Published | 2020-04-06T12:08:40 |
| Patch Date | 2020-04-04 |
| Last Updated | 2024-09-17T03:07:51 |
Community Chatter & Buzz