Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.
The vulnerability stems from improperly configured permissions (CWE-732) in the nav2_mppi_controller component of the ROS2 navigation2 system. An attacker can upload a specially crafted script that will be executed by the vulnerable component without proper permission verification or requester identity authentication. The lack of authentication requirement (PR:N, UI:N) means that the attack can be conducted remotely over the network without any user interaction.
Successful exploitation of the vulnerability allows an attacker to remotely execute arbitrary code (RCE) on the target system, which may lead to complete takeover of the robotic platform, loss of data confidentiality and integrity, and disruption of service availability.
Patches available from the manufacturer should be applied according to the references. Details of the fix are available in the project repository at https://github.com/ros-navigation/navigation2/pull/4463. Additionally, it is recommended to isolate ROS2 communication interfaces from public networks, use firewalls, and restrict network access to ROS2 nodes exclusively to trusted hosts.
Open Robotics Robot Operating System 2 (ROS2) navigation2, humble version — nav2_mppi_controller component
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpenrobotics Robot Operating System
APPOpenrobotics2
Related vulnerabilities
Use-after-free w ROS2 Nav2 humble — zdalny exploit przez nav2_amcl
Heap overflow w procesie nav2_amcl systemu ROS2 Nav2
Use-after-free w ROS2 Nav2 — zdalny atak przez parametr /amcl z_rand
Use-after-free w ROS2 Nav2 humble poprzez proces nav2_amcl
Use-after-free w ROS2 Nav2 — zdalny atak przez zmianę parametru AMCL