Remote Code Execution Vulnerability in Universal Robots Controllers
CVE-2018-10635
9.8CRITICAL
What is CVE-2018-10635?
In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, specific TCP ports (30001 to 30003) expose a security vulnerability that allows arbitrary URScript code execution. An attacker with network access to these ports could exploit this flaw to execute malicious code, potentially resulting in unauthorized root access to the system. This vulnerability highlights the importance of securing network interfaces and ensuring that only trusted users have access to sensitive functionalities.
Affected Version(s)
Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
