CRITICAL🇵🇱 Wersja polska

CVE-2024-41645

CVSS 9.8v3.1pub. 2024-12-06upd. 2024-12-13

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.

🤖 AI Analysis
How it works

Misconfigured permissions in the nav2_amcl component of the ROS2 navigation2 system allow an attacker to deliver a crafted script that is executed in the context of a running node. The attacker can thus inject malicious payload without needing any system privileges. The access control mechanism does not sufficiently restrict operations on scripts or related resources, opening a path to full takeover of the process.

Impact

An attacker can execute arbitrary code in the context of a vulnerable ROS2 node, leading to complete compromise of confidentiality, integrity, and availability of the robotic system.

Mitigation & patch

Security patches provided by the vendor should be applied according to references — a fix was proposed in pull request #4521 in the ros-navigation/navigation2 repository on GitHub. It is recommended to monitor the patch status and update to a version containing the patch immediately after its release.

Who is affected

Open Robotics Robot Operating System 2 (ROS2) navigation2, humble version — nav2_amcl component

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Openrobotics Robot Operating System

    APP
    Openrobotics
    2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-38924CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 humble — zdalny exploit przez nav2_amcl

CVE-2024-38922CRITICAL9.8PL ✓same product

Heap overflow w procesie nav2_amcl systemu ROS2 Nav2

CVE-2024-38921CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 — zdalny atak przez parametr /amcl z_rand

CVE-2024-38923CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 humble poprzez proces nav2_amcl

CVE-2024-38925CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 — zdalny atak przez zmianę parametru AMCL