Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could ‘cook’ a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10290
Reference (s):
- https://github.com/aliasrobotics/RVD/issues/1495
- URL: https://github.com/aliasrobotics/RVD/issues/1495

