CVE-2020-10287 affects ABB IRC5 controllers and associated IRB140 robots, stemming from the use of publicly documented default credentials for the UAS service. This critical vulnerability (CVSS 9.8) allows unauthenticated remote attackers to gain full control over affected systems, leading to complete compromise of confidentiality, integrity, and availability. While ABB considers this a documented feature, widespread use of these defaults in production environments creates a significant exposure. There is no evidence of active exploitation or public exploit code, but the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:abb:irb140_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:abb:irc5_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.