CVE-2023-24012: Data Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Open DDS
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7verify function used to validate S/MIME signatures.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24012?
CVE-2023-24012 is classified as a critical vulnerability due to its potential to allow full control over a secure DDS databus system.
How do I fix CVE-2023-24012?
To mitigate CVE-2023-24012, update to the latest version of OpenDDS that addresses the PKCS#7 certificate validation vulnerabilities.
What systems are affected by CVE-2023-24012?
CVE-2023-24012 affects systems utilizing OpenDDS that rely on secure DDS databus configurations and PKCS#7 certificates.
What are the consequences of exploiting CVE-2023-24012?
Exploitation of CVE-2023-24012 can lead to unauthorized access and full control over the impacted secure DDS databus system.
How does CVE-2023-24012 affect security protocols?
CVE-2023-24012 undermines the integrity of security protocols in DDS by allowing attackers to craft malicious nodes with valid certificates.