CVE-2021-37146: High severity ros ros-comm vulnerability
Published Sep 28, 2021
·Updated
An infinite loop in Open Robotics roscomm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in roscomm via a crafted XMLRPC call.
Affected Software
2 affected components
ros ros-comm<=1.4.11
ros ros-comm>=1.15.0<=1.15.11
Event History
Sep 28, 2021
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-37146?
The severity of CVE-2021-37146 is high.
2
How does CVE-2021-37146 affect ROS Melodic and ROS Noetic?
CVE-2021-37146 affects ROS Melodic through 1.4.11 and ROS Noetic through 1.15.11.
3
How can remote attackers exploit CVE-2021-37146?
Remote attackers can exploit CVE-2021-37146 by causing a Denial of Service in ros_comm via a crafted XMLRPC call.
4
Are there any fixes available for CVE-2021-37146?
For ROS Melodic, refer to the links provided for the new packages. For ROS Noetic, refer to the links provided for the new packages.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-37146?
The Common Weakness Enumeration (CWE) ID for CVE-2021-37146 is 835.