CRITICAL🇵🇱 Wersja polska

CVE-2024-38921

CVSS 9.8v3.1pub. 2024-12-06upd. 2024-12-17

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_rand ` .

🤖 AI Analysis
How it works

The vulnerability is triggered by remotely sending a request to change the value of the dynamic parameter `/amcl z_rand` to the nav2_amcl process. This request leads to a use-after-free situation in which the code references an area of memory that has already been freed. Since the attack vector is network-based, it does not require authentication or user interaction (AC:L, PR:N, UI:N).

Impact

An attacker can gain full control over the vulnerable process, potentially leading to disclosure of sensitive data, data modification, or system disruption (loss of confidentiality, integrity, and availability). In the context of robotic systems, this could result in takeover of physical device control.

Mitigation & patch

Patches available from the vendor should be applied according to the references. A related pull request is available in the navigation2 repository (PR #4397). It is also recommended to restrict network access to ROS2 interfaces through firewall or network isolation, so that dynamic parameter change requests are accessible only from trusted hosts.

Who is affected

Open Robotics Robot Operating System 2 (ROS2) and Nav2 version humble

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Openrobotics Robot Operating System

    APP
    Openrobotics
    2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2024-38925CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 — zdalny atak przez zmianę parametru AMCL

CVE-2024-38923CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 humble poprzez proces nav2_amcl

CVE-2024-38922CRITICAL9.8PL ✓same product

Heap overflow w procesie nav2_amcl systemu ROS2 Nav2

CVE-2024-38924CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 humble — zdalny exploit przez nav2_amcl

CVE-2024-38926CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 humble via proces nav2_amcl