CVE Vulnerabilities

CVE-2018-17933

Published: Oct 30, 2018 | Modified: Oct 09, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execute commands that are outside the scope of their privileges and within the scope of an admin account. If an attacker has access to VGo XAMPP Client credentials, they may be able to execute admin commands on the connected robot.

Affected Software

Name Vendor Start Version End Version
Vgo_firmware Vecna 3.0.3.52164 (including) 3.0.3.52164 (including)
Vgo_firmware Vecna 3.0.3.53662 (including) 3.0.3.53662 (including)

References