CVE-2022-48198: Critical severity ntpd driver vulnerability
The ntpddriver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled timereftopic parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-48198?
CVE-2022-48198 is classified as a medium severity vulnerability.
How do I fix CVE-2022-48198?
To remediate CVE-2022-48198, update the ntpd_driver component to version 1.3.0 or 2.2.0 or later.
Which versions are affected by CVE-2022-48198?
CVE-2022-48198 affects ntpd_driver versions prior to 1.3.0 and 2.x versions between 2.0.0 and 2.2.0.
What are the consequences of CVE-2022-48198?
Exploitation of CVE-2022-48198 may allow an attacker to alter a robot's behavior by controlling a different node in the same ROS application.
Who is impacted by CVE-2022-48198?
Users of the ntpd_driver component in Robot Operating System (ROS) versions prior to the patched releases are impacted by CVE-2022-48198.