Medium severity6.4NVD Advisory· Published Jun 24, 2020· Updated Jun 17, 2026
CVE-2020-10277
CVE-2020-10277
Description
There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- cpe:2.3:o:easyrobotics:er-flex_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:easyrobotics:er-lite_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:easyrobotics:er-one_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:easyrobotics:er200_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mobile-industrial-robots:mir1000_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mobile-industrial-robots:mir100_firmware:*:*:*:*:*:*:*:*Range: <=2.8.1.1
- cpe:2.3:o:mobile-industrial-robots:mir200_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mobile-industrial-robots:mir250_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mobile-industrial-robots:mir500_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:uvd-robots:uvd_firmware:-:*:*:*:*:*:*:*
- Mobile Industrial Robots A/S/MiR100v5Range: v2.8.1.1 and before
Patches
Vulnerability mechanics
References
1- github.com/aliasrobotics/RVD/issues/2562nvdThird Party Advisory
News mentions
0No linked articles in our index yet.