Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 5.25.1
affected
Description
OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.21.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.
Problem types
CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Product status
Any version before 5.25.1
Credits
Vera Mens of Claroty Team82
References
www.universal-robots.com/...ation-protocol/dashboard-server/