Alias Robotics S.L.
First CVE: Apr 6, 2020Active for: 6 years
29
CVEs Published
More CVEs Published than 48% of tracked CNAs
29.0
Avg CVEs / Year
More Avg CVEs / Year than 76% of tracked CNAs
8.5
Avg CVSS Score
Higher Avg CVSS Score than 94% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Alias Robotics S.L. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2020
6 years ago
Most Recent CVE
Nov 6, 2020
2,086 days ago
Top CVEs
All CVEs published by Alias Robotics S.L. as a CNA, regardless of affected vendor or product.
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10285CRITICAL The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout a | Jul 15, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-10276CRITICAL The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling t | Jun 24, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-10288CRITICAL IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as | Jul 15, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-10287CRITICAL The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that | Jul 15, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-10284CRITICAL No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but | Jul 15, 2020 | 9.1 | 29 | NO | NO |
CVE-2020-10265CRITICAL Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server | Apr 6, 2020 | 9.4 | 29 | NO | NO |
CVE-2020-10286HIGH the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted acc | Jul 15, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-10271CRITICAL MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is th | Jun 24, 2020 | 9.8 | 27 | NO | NO |
CVE-2020-10272CRITICAL MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers | Jun 24, 2020 | 9.8 | 25 | NO | NO |
CVE-2020-10283CRITICAL The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order to maintain backwards compatibi | Aug 20, 2020 | 9.8 | 24 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA29 CVEs
14%
38%
48%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (79.3%)
Unknown0 (0.0%)
Physical4 (13.8%)
Adjacent Network2 (6.9%)
Attack Complexity
Low28 (96.6%)
High1 (3.4%)
Unknown0 (0.0%)
User Interaction
None29 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (6.9%)
High0 (0.0%)
None27 (93.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (29 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Alias Robotics S.L. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Alias Robotics S.L. as a CNA — matched by CVE ID, not by organization name.