Security Advisory

CVE-2020-10290

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-08-21 15:05:19
Last updated 2024-09-16 19:15:10
Assigner Alias
State PUBLISHED

Description

Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could cook a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system