RVD icon indicating copy to clipboard operation
RVD copied to clipboard

RVD#9: Improper authorization mechanism in SoftBank's Pepper and NAO robots

Open aliasbot opened this issue 7 years ago • 3 comments

{
    "id": 9,
    "title": "RVD#9: Improper authorization mechanism in SoftBank's Pepper and NAO robots ",
    "type": "vulnerability",
    "description": " Improper authorization mechanism in SoftBank's Pepper and NAO robots could allow remote attackers to gain unrestricted access to robot configuration and sensor data via an unsecured object proxy mechanism. Credits to: Cesar Cerrudo and Lucas Apa from IOActive",
    "cwe": "CWE-285",
    "cve": "None",
    "keywords": [
        "robot: NAO",
        "robot: Pepper",
        "vendor: SoftBank Robotics",
        "vulnerability"
    ],
    "system": "NAO / Pepper NAOqi",
    "vendor": "SoftBank Robotics",
    "severity": {
        "rvss-score": 8.2,
        "rvss-vector": "RVSS:1.0/AV:IN/AC:L/PR:N/UI:N/Y:M/S:U/C:H/I:H/A:L/H:U",
        "severity-description": "High",
        "cvss-score": 9.4,
        "cvss-vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
    },
    "links": [
        "https://github.com/aliasrobotics/RVD/issues/14"
    ],
    "flaw": {
        "phase": "testing",
        "specificity": "general-issue",
        "architectural-location": "platform code",
        "application": "NaoQi",
        "subsystem": "N/A",
        "package": "N/A",
        "languages": "None",
        "date-detected": "2017-03-01",
        "detected-by": "Cesar Cerrudo and Lucas Apa from IOActive",
        "detected-by-method": "Testing dynamic",
        "date-reported": "2017-03-01",
        "reported-by": "Alias Robotics",
        "reported-by-relationship": "Security researcher",
        "issue": "https://github.com/aliasrobotics/RVD/issues/14",
        "reproducibility": "Always",
        "trace": "N/A",
        "reproduction": "N/A",
        "reproduction-image": "N/A"
    },
    "exploitation": {
        "description": "N/A",
        "exploitation-image": "N/A",
        "exploitation-vector": "N/A"
    },
    "mitigation": {
        "description": "N/A",
        "pull-request": "N/A",
        "date-mitigation": "N/A",
    }
}

aliasbot avatar Jul 30 '18 20:07 aliasbot

Feedback (automatically generated):

  • FIXME: Flaw not identified as a vulnerability, weakness or exposure. Have you included # Vulnerability (or Weakness or Exposure) report at the top of the ticket?, see Vulnerability report template for more information or review other tickets to get inspiration

Please review the feedback above. Once addressed, either request the removal of the malformed label to trigger another automatic review.

github-actions[bot] avatar Oct 27 '19 17:10 github-actions[bot]

Feedback (automatically generated):

  • FIXME: Robot or Robot component not present in summary table or invalid, see Vulnerability report template for more information or review other tickets and get inspiration

Please review the feedback above. Once addressed, either request the removal of the malformed label to trigger another automatic review.

github-actions[bot] avatar Oct 29 '19 13:10 github-actions[bot]

Triage Complete.

glerapic avatar Jun 02 '20 09:06 glerapic