Description
Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR Robots allows authenticated users to extract files from the robot file system via a crafted API request.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version before 3.0.0
Credits
Lockheed Martin Red Team
References
mobile-industrial-robots.com/...ty-advisories/path-traversal
supportportal.mobile-industrial-robots.com/...ecurity-guide/