Er Flex
Vendor:
First CVE: Jun 24, 2020 · Active for 6 years
7
Total CVEs
More Total CVEs than 83% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
8.7
Avg CVSS
Higher Avg CVSS than 78% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Er Flex over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2020
6 years ago
Most Recent CVE
Jun 24, 2020
2,221 days ago
CVE Severity & Scoring
Er Flex7 CVEs
14%
14%
71%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical1 (14.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10271CRITICAL MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is th | Jun 24, 2020 | 9.8 | 27 | NO | NO |
CVE-2020-10272CRITICAL MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers | Jun 24, 2020 | 9.8 | 25 | NO | NO |
CVE-2020-10279CRITICAL MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for rob | Jun 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-10270CRITICAL Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Crede | Jun 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-10269CRITICAL One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode. Creden | Jun 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-10273HIGH MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attac | Jun 24, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-10278MEDIUM The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operat | Jun 24, 2020 | 4.6 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Er Flex
Top CWEs
Versions
No cataloged versions.