aliasrobotics / RVD

Robot Vulnerability Database. An archive of robot vulnerabilities and bugs.
https://aliasrobotics.com
GNU General Public License v3.0
173 stars 31 forks source link

RVD#9: Improper authorization mechanism in SoftBank's Pepper and NAO robots #9

Open aliasbot opened 6 years ago

aliasbot commented 6 years ago

{
    "id": 9,
    "title": "RVD#9: Improper authorization mechanism in SoftBank's Pepper and NAO robots ",
    "type": "vulnerability",
    "description": " Improper authorization mechanism in SoftBank's Pepper and NAO robots could allow remote attackers to gain unrestricted access to robot configuration and sensor data via an unsecured object proxy mechanism. Credits to: Cesar Cerrudo and Lucas Apa from IOActive",
    "cwe": "CWE-285",
    "cve": "None",
    "keywords": [
        "robot: NAO",
        "robot: Pepper",
        "vendor: SoftBank Robotics",
        "vulnerability"
    ],
    "system": "NAO / Pepper NAOqi",
    "vendor": "SoftBank Robotics",
    "severity": {
        "rvss-score": 8.2,
        "rvss-vector": "RVSS:1.0/AV:IN/AC:L/PR:N/UI:N/Y:M/S:U/C:H/I:H/A:L/H:U",
        "severity-description": "High",
        "cvss-score": 9.4,
        "cvss-vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
    },
    "links": [
        "https://github.com/aliasrobotics/RVD/issues/14"
    ],
    "flaw": {
        "phase": "testing",
        "specificity": "general-issue",
        "architectural-location": "platform code",
        "application": "NaoQi",
        "subsystem": "N/A",
        "package": "N/A",
        "languages": "None",
        "date-detected": "2017-03-01",
        "detected-by": "Cesar Cerrudo and Lucas Apa from IOActive",
        "detected-by-method": "Testing dynamic",
        "date-reported": "2017-03-01",
        "reported-by": "Alias Robotics",
        "reported-by-relationship": "Security researcher",
        "issue": "https://github.com/aliasrobotics/RVD/issues/14",
        "reproducibility": "Always",
        "trace": "N/A",
        "reproduction": "N/A",
        "reproduction-image": "N/A"
    },
    "exploitation": {
        "description": "N/A",
        "exploitation-image": "N/A",
        "exploitation-vector": "N/A"
    },
    "mitigation": {
        "description": "N/A",
        "pull-request": "N/A",
        "date-mitigation": "N/A",
    }
}
github-actions[bot] commented 4 years ago

Feedback (automatically generated):

Please review the feedback above. Once addressed, either request the removal of the malformed label to trigger another automatic review.

github-actions[bot] commented 4 years ago

Feedback (automatically generated):

Please review the feedback above. Once addressed, either request the removal of the malformed label to trigger another automatic review.

glerapic commented 4 years ago

Triage Complete.