RobotRisk Autonomous Systems Incident & Risk Register
RobotRisk / KUKA / 2021-07-27

CISA advisory: hard-coded credentials in KUKA KR C4 robot controller (CVSS 9.8)

S1 · 07/27
2021 · KUKA

Record

CompanyKUKA
Categorymachinery oem
Typecyber
Date07/27
2021
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
SeverityS1 (near-miss / disclosed vulnerability)
ScaleKUKA KR C4 controller product line
Confidencehigh
VerificationCited source on file; not independently re-verified
SourceCISA ICS-CERT

What happened

CISA published ICSA-21-208-01 detailing a critical hard-coded-credentials flaw in KUKA KR C4 controllers (KSS versions prior to 8.7) that could give an attacker full read/write/delete access to sensitive system folders; no known public exploitation, patch issued.

KUKA record context

Entries by year and severity

012021 S1: 1121
S1S2S3S4S5

By incident type

By severity

KUKA vs machinery oem alternatives

machinery oem context

machinery oem: entries by year

232015 S5: 22152017 S2: 11172021 S1: 22212024 S1: 11242026 S1: 3326
S1S2S3S4S5

machinery oem: failure modes

machinery oem: most entries

cyber context

cyber: by category

cyber: by year

cyber: severity profile

Comparable cyber events in machinery oem

SevDateCompanyEvent
S12026-09Mitsubishi Electric (Automation)CISA ICS advisories: 1 affecting robot/controller products
S12026-09FANUCCISA ICS advisories: 2 affecting robot/controller products
S12026-09ABBCISA ICS advisories: 2 affecting robot/controller products
S12021-08-31FANUCCISA advisory: buffer overflow / integer coercion vulnerabilities in FANUC robot controllers
S22017-05ABBResearchers demonstrate remote hack of ABB IRB140 industrial robot causing unsafe physical movement

Other KUKA entries

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs