rvd-bot

Results 48 issues of rvd-bot

```yaml id: 3337 title: Service DoS through arbitrary pointer dereferencing on KUKA simulator type: vulnerability description: "Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and...

vulnerability
severity: high
vendor: KUKA
vendor: Visual Components
version: 2.0.8
robot component: Visual Components

```yaml id: 3336 title: 'RVD#3336: System information disclosure without authentication on KUKA simulators' type: vulnerability description: "Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and...

severity: medium
vulnerability
vendor: KUKA
vendor: Visual Components
version: 2.0.8
robot component: Visual Components

```yaml id: 3320 title: 'RVD#3320: XML External Entity (XXE) attacks via unspecified vectors on Mitsubishi products' type: vulnerability description: Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver....

vulnerability
triage
vendor: Mitsubishi Electric

```yaml id: 3319 title: 'RVD#3319: Uncontrolled resource consumption vulnerability in Mitsubishi products allows denial of service (DoS) attacks' type: vulnerability description: Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering...

vulnerability
triage
vendor: Mitsubishi Electric

```yaml { "id": 1487, "title": "RVD#1487: No integrity checks on UR+ platform artifacts when installed in the robot", "type": "vulnerability", "description": "UR+ (Universal Robots+) is a platform of hardware and...

severity: critical
vulnerability
vendor: Universal Robots
robot: UR3
robot: UR5
robot: UR10
robot component: Universal Robots Controller
CWE-353
CVE-2020-10266

```yaml id: 2573 title: 'RVD#2573: The DBPOWER U818A WIFI quadcopter drone provides FTP access over ' type: vulnerability description: The DBPOWER U818A WIFI quadcopter drone provides FTP access over its...

severity: medium
vulnerability
vendor: DBPOWER
robot: DBPOWER U818A

```yaml id: 1495 title: 'RVD#1495: Universal Robots URCaps execute with unbounded privileges' type: vulnerability description: Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and...

severity: critical
vulnerability
vendor: Universal Robots
robot: UR3
robot: UR5
robot: UR10
robot component: Universal Robots Controller

```yaml id: 3327 title: 'RVD#3327: No authentication required for accesing ABB IRC5 FTP server' type: vulnerability description: IRC5 exposes an ftp server (port 21). Upon attempting to gain access you...

severity: critical
vulnerability
vendor: ABB
robot component: ABB IRC5 OPC Server
robot: ABB IRB140
robot component: Robotware
robot component: VxWorks

```yaml id: 3326 title: 'RVD#3326: Hardcoded default credentials on IRC 5 OPC Server' type: exposure description: The IRC5 family with UAS service enabled comes by default with credentials that can...

severity: critical
vulnerability
vendor: ABB
robot component: ABB IRC5 OPC Server
robot: ABB IRB140
robot component: Robotware
robot component: VxWorks

```yaml id: 3324 title: 'RVD#3324: ABB IRC5 FTP daemon in VxWorks does not close the TCP connection after a number of failed login attempts' type: vulnerability description: The FTP daemon...

severity: critical
vulnerability
vendor: ABB
robot component: ABB IRC5 OPC Server
vendor: WindRiver
robot: ABB IRB140
robot component: Robotware
robot component: VxWorks