CVE-2019-19625: Infoleak
Published Dec 6, 2019
·Updated
SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2) leaks node information due to a leaky default configuration as indicated in the policy/defaults/dds/governance.xml document.
Affected Software
1 affected component
ros SROS2=0.8.1
Event History
Dec 6, 2019
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2019-19625?
CVE-2019-19625 is classified as a medium severity vulnerability.
2
How can I fix CVE-2019-19625?
To fix CVE-2019-19625, update SROS 2 to a version prior to 0.8.1 or modify the default configuration settings in governance.xml.
3
What type of information is leaked in CVE-2019-19625?
CVE-2019-19625 leaks node information due to a default configuration issue.
4
Which version of SROS 2 is affected by CVE-2019-19625?
CVE-2019-19625 affects SROS 2 version 0.8.1.
5
What is SROS 2 and its relation to CVE-2019-19625?
SROS 2 provides tools for generating and distributing keys for ROS 2, and CVE-2019-19625 relates to its security configuration issues.