CVE-2023-24010: Data Distribution Service (DDS) Chain of Trust (CoT) violation in Fast DDS
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7verify function used to validate S/MIME signatures.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24010?
CVE-2023-24010 has been classified as a critical vulnerability due to its potential to allow full control of a secure DDS databus system.
How do I fix CVE-2023-24010?
To mitigate CVE-2023-24010, ensure that the configuration settings for PKCS#7 certificate validation are securely implemented and up to date.
Who is affected by CVE-2023-24010?
CVE-2023-24010 affects users of eProsima Fast DDS that utilize DDS participants or ROS 2 nodes with vulnerable configuration settings.
What kind of attacks can CVE-2023-24010 enable?
CVE-2023-24010 can enable attackers to craft malicious DDS participants or nodes to compromise the integrity and security of the databus system.
What are the mitigations for CVE-2023-24010?
Mitigations for CVE-2023-24010 include ensuring proper validation of certificates and regular security audits of the DDS configuration.