The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Link | Tags |
---|---|
https://github.com/aliasrobotics/RVD/issues/3322 | third party advisory issue tracking |