aliasrobotics / RVD

Robot Vulnerability Database. An archive of robot vulnerabilities and bugs.
https://aliasrobotics.com
GNU General Public License v3.0
179 stars 31 forks source link

RVD#86: Wifi and XMPP plaintext password storage could lead to sensitive data loss #86

Open aliasbot opened 6 years ago

aliasbot commented 6 years ago
{
    "id": 86,
    "title": "RVD#86: Wifi and XMPP plaintext password storage could lead to sensitive data loss",
    "type": "vulnerability",
    "description": "An attacker could dump the wifi and XMPP credentials stored in plaintext by the robot, by using the already present code execution vulnerability via the usb port. Leveraging to compromise of the network where the robot is connected.",
    "cwe": "CWE-Plaintext Storage of a Password (CWE-256)",
    "cve": "None",
    "keywords": [
        "malformed",
        "robot",
        "robot: Vgo",
        "severity: high",
        "state: new",
        "vendor: Vecna",
        "vulnerability"
    ],
    "system": "Vgo",
    "vendor": "Vecna",
    "severity": {
        "rvss-score": "None",
        "rvss-vector": "RVSS:1.0/AV:PP/AC:H/PR:N/UI:N/Y:Z/S:C/C:H/I:H/A:H/H:U",
        "severity-description": "",
        "cvss-score": 0,
        "cvss-vector": ""
    },
    "links": [
        "https://github.com/aliasrobotics/RVD/issues/86"
    ],
    "flaw": {
        "phase": "unknown",
        "specificity": "N/A",
        "architectural-location": "N/A",
        "application": "N/A",
        "subsystem": "N/A",
        "package": "N/A",
        "languages": "None",
        "date-detected": "2018-10-17",
        "detected-by": "",
        "detected-by-method": "N/A",
        "date-reported": "2018-10-17",
        "reported-by": "",
        "reported-by-relationship": "N/A",
        "issue": "https://github.com/aliasrobotics/RVD/issues/86",
        "reproducibility": "",
        "trace": null,
        "reproduction": "",
        "reproduction-image": ""
    },
    "exploitation": {
        "description": "",
        "exploitation-image": "",
        "exploitation-vector": ""
    },
    "mitigation": {
        "description": "",
        "pull-request": "",
        "date-mitigation": null
    }
}
github-actions[bot] commented 5 years ago

Feedback (automatically generated):

Please review the feedback above. Once addressed, either request the removal of the malformed label to trigger another automatic review.

github-actions[bot] commented 5 years ago

Feedback (automatically generated):

Please review the feedback above. Once addressed, either request the removal of the malformed label to trigger another automatic review.