Ufactory develops collaborative robotic arms in its xArm product line, where disclosed vulnerabilities cluster around authentication and access-control issues including reliance on security through obscurity, improper privilege management, and weak authentication-rate limiting. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ufactory over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10285CRITICAL The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout a | Jul 15, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-10284CRITICAL No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but | Jul 15, 2020 | 9.1 | 29 | NO | NO |
CVE-2020-10286HIGH the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted acc | Jul 15, 2020 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ufactory.
Media articles that mention a CVE ID that affects a product developed by Ufactory — matched by CVE ID, not by vendor name.