Description
MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowing low-privilege users to create notes which are intended only for administrative users.
Problem types
CWE-863: Incorrect Authorization
Product status
Any version before 3.0.0
Any version before 3.0.0
Credits
Lockheed Martin Red Team
References
a.storyblok.com/f/230581/x/46f48d3787/msa-15.pdf
supportportal.mobile-industrial-robots.com/...ecurity-guide/