CVE-2020-10255 and -10268

  • Hello,


    Over a year ago the Spanish company AliasRobotics found 2 cybersecurity vulnerabilities in Kuka robots (issues CVE-2020-10255 and CVE-2020-10268). I searched on the Kuka website for any information about this, but I found nothing. So I was wondering whether there's updates available to fix these issues? I'm quite new to Kuka so may not have searches the right places, if you have any pointers that would be great.

  • check pinned topic READ FIRST.

    it covers number of things including access to Xpert portal which is where any user documentation is found as well as any news or patches.

    1) read pinned topic: READ FIRST...

    2) if you have an issue with robot, post question in the correct forum section... do NOT contact me directly

    3) read 1 and 2

  • So, one of those seems to be a simple RowHammer vulnerability, which isn't really an issue for a KUKAbot in most circumstances. Properly isolating the KRC if it is handling any confidential data that RowHammer might expose should be a fairly trivial exercise.


    The other is simply that the robot can be brought to a halt using the Task Manager, after which "Brake recalibration must be performed." There's no details on that, but I'm betting this just means a Brake Test, which can be performed easily enough, without requiring special KUKA skills and/or equipment.


    Frankly, neither of these seem at all serious, unless the second CVE is leaving out a LOT of details. Either one can be made very difficult to exploit simply by using proper security procedures and controlling password access, possibly adding a secure firewall between the KRC and the general network if one is really paranoid.

Advertising from our partners