← Back to CVE List
Vulnerability Intelligence Report
RVD#1443: UR dashboard server enables unauthenticated remote control of core robot functions

CVE-2020-10265

Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starting/stopping programs, shutdown, reset safety and more. The DashBoard server is not protected by any kind of authentication or authorization.

No Active Exploit Signals
CVSS Base Score
9.4
CRITICAL
Exploitability:3.9
Impact Score:5.5
EPSS Probability:1.43%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-306 ↗CWE-306 (Missing Authentication for Critical Function)

Affected Products & Versions

Vendor Product Affected Versions
Universal Robots Universal Robots Robot Controllers CB 2, CB3, e-series unspecified (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.430%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAlias Robotics S.L. · Vendor · Spain
Reserved2020-03-10T00:00:00
Published2020-04-06T12:08:40
Patch Date2020-04-04
Last Updated2024-09-17T03:07:51

LINK COPIED TO CLIPBOARD