Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.
Improperly configured permissions (CWE-281) in the nav2_costmap_2d component allow an attacker to deliver a crafted script that is executed by the vulnerable process without proper permission verification. The attack can be conducted remotely over the network without requiring an account or permissions in the system and without user interaction. This mechanism gives the attacker full control over code execution in the context of the vulnerable service.
An attacker can remotely execute arbitrary code (RCE) on a system running the vulnerable service, which may lead to complete takeover of the ROS2 node, data disclosure, modification of robot configuration, or disruption of its operation.
Patches available from the vendor should be applied according to references — a fix was proposed through pull request #4495 in the ros-navigation/navigation2 repository on GitHub. It is recommended to update to a version containing this fix and restrict network access to ROS2 interfaces using a firewall or network segmentation.
Open Robotics Robot Operating System 2 (ROS2) — navigation2 package in humble version (nav2_costmap_2d)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpenrobotics Robot Operating System
APPOpenrobotics2
Related vulnerabilities
Use-after-free w ROS2 Nav2 humble — zdalny exploit przez nav2_amcl
Heap overflow w procesie nav2_amcl systemu ROS2 Nav2
Use-after-free w ROS2 Nav2 — zdalny atak przez parametr /amcl z_rand
Use-after-free w ROS2 Nav2 humble poprzez proces nav2_amcl
Use-after-free w ROS2 Nav2 — zdalny atak przez zmianę parametru AMCL