RVD icon indicating copy to clipboard operation
RVD copied to clipboard

Robot Vulnerability Database. An archive of robot vulnerabilities and bugs.

Results 105 RVD issues
Sort by recently updated
recently updated
newest added

```yaml { "id": 39, "title": "RVD#39: Remote Firmware Upgrade in Alpha 1S As", "type": "vulnerability", "description": "It is possible to remotely upgrade the Alpha 1S firmware by sending an undocumented...

robot
severity: critical
state: new
vulnerability
vendor: UBTech Robotics
robot: Alpha 1S
Ubtech Robotics

The workflow push.yml is referencing action actions/checkout using references v1. However this reference is missing the commit [a6747255bd19d7a757dbdda8c654a9f84db19839](https://github.com/actions/checkout/commits/a6747255bd19d7a757dbdda8c654a9f84db19839) which may contain fix to the some vulnerability. The vulnerability fix that...

The workflow issues_management.yml is referencing action actions/checkout using references v1. However this reference is missing the commit [a6747255bd19d7a757dbdda8c654a9f84db19839](https://github.com/actions/checkout/commits/a6747255bd19d7a757dbdda8c654a9f84db19839) which may contain fix to the some vulnerability. The vulnerability fix that...

```yaml id: 3316 title: 'RVD#3316: No authentication in MAVLink protocol' type: vulnerability description: The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization)...

severity: critical
components software
vulnerability
robot component: PX4
robot component: Ardupilot
robot component: MAVLink
version: 1.0

```yaml id: 449 title: 'RVD#449: Lack of Forward Secrecy (FS) support in handshake algorithms' type: weakness description: "In the DDS protocol, only two types of algorithms, \u201CDH+MODP-2048-256\u201D\ \ and \u201CECDH+prime256v1-CEUM\u201D,...

components software
vulnerability
robot component: ROS2
vendor: eProsima
vendor: RTI
vendor: ADLINK
robot component: DDS
triage

```yaml id: 451 title: 'RVD#451: DDS cryptographic plugin, AES_GCM subject to forgery, key recovery and timing attacks, and nonce replay attacks' type: vulnerability description: For the cryptographic plugin, AES_GCM and...

components software
vulnerability
robot component: ROS2
robot component: FastRTPS
vendor: eProsima
vendor: RTI
vendor: ADLINK
robot component: DDS
triage

```yaml id: 450 title: 'RVD#450: DDS authentication plugin weakness in prime256v1 curves might lead to data to side channel attacks' type: weakness description: For the authentication plug-in, a participant is...

components software
vulnerability
robot component: ROS2
robot component: FastRTPS
vendor: eProsima
vendor: RTI
vendor: ADLINK
robot component: DDS
triage

```yaml id: 453 title: 'RVD#453: Prediction number attacks on sequence number during RTPS initialization (affects authentication and access DDS security plugins)' type: weakness description: "The DDS Security standard states that,...

components software
vulnerability
robot component: ROS2
robot component: FastRTPS
vendor: eProsima
vendor: RTI
vendor: ADLINK
robot component: DDS
CWE-340
triage

```yaml { "id": 10, "title": "RVD#10: Relative Path Traversal vulnerability in SREA-01 and SREA-50", "type": "vulnerability", "description": " Relative Path Traversal vulnerability in SREA-01 and SREA-50 legacy remote monitoring tools...

components hardware
severity: critical
vulnerability
vendor: ABB
review

```yaml { "id": 12, "title": "RVD#12: Authentication bypass vulnerability in SoftBank's Pepper and NAO robots's web console", "type": "vulnerability", "description": " An authentication bypass vulnerability in SoftBank's Pepper and NAO...

robot
vulnerability
robot: Pepper
vendor: Softbank Robotics
robot: NAO
severity: high