In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbitrary URScript code and execute the code. This enables a remote attacker who has access to the ports to remotely execute code that may allow root access to be obtained.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/104710 | vdb entry third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-18-191-01 | us government resource third party advisory mitigation |