VulnerabilityModified
CVE-2022-2675
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication.
MEDIUM 6.5EPSS 0.50%
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- unitree/go 1 firmware
- Source
- cve@rapid7.com
References
- https://fccid.io/2A5PE-YUSHU001/Users-Manual/User-Manual-5810729Product, Third Party Advisory
- https://twitter.com/d0tslash/status/1555326302462394370Third Party Advisory
- https://www.mybotshop.de/Datasheet/Unitree_A1_User_Manual_v1.0.pdfProduct, Third Party Advisory
- https://fccid.io/2A5PE-YUSHU001/Users-Manual/User-Manual-5810729Product, Third Party Advisory
- https://twitter.com/d0tslash/status/1555326302462394370Third Party Advisory
- https://www.mybotshop.de/Datasheet/Unitree_A1_User_Manual_v1.0.pdfProduct, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.