CVE-2020-10287 Information

Description

The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however out of our research we found multiple production systems running these exact default credentials and consider thereby this an exposure that should be mitigated. Moreover future deployments should consider that these defaults should be forbidden (user should be forced to change them).

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://github.com/aliasrobotics/RVD/issues/3326

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: