Home/Product/aliasrobotics mir500 firmware
Product

aliasrobotics mir500 firmware

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-10280
all versions
The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively b
7.5HIGH
CVE-2020-10279
<= 2.8.1.1
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this o
9.8CRITICAL
CVE-2020-10278
<= 2.8.1.1
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot
4.6MEDIUM
CVE-2020-10277
all versions
There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible fil
6.4MEDIUM
CVE-2020-10276
all versions
The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be u
9.8CRITICAL
CVE-2020-10275
all versions
The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Giv
9.8CRITICAL
CVE-2020-10274
all versions
The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentia
7.1HIGH
CVE-2020-10273
<= 2.8.1.1
MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifac
7.5HIGH
CVE-2020-10272
<= 2.8.1.1
MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without
9.8CRITICAL
CVE-2020-10271
<= 2.8.1.1
MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all
9.8CRITICAL
CVE-2020-10270
<= 2.8.1.1
Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the
9.8CRITICAL
CVE-2020-10269
<= 2.8.1.1
One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-con
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin