CVE-2023-33566: Critical severity robot operating system (ros) vulnerability

Published Jun 27, 2023
·
Updated

An unauthorized node injection vulnerability has been identified in ROS2 Foxy Fitzroy versions where ROSVERSION is 2 and ROSPYTHONVERSION is 3. This vulnerability could allow a malicious user to inject malicious ROS2 nodes into the system remotely. Once injected, these nodes could disrupt the normal operations of the system or cause other potentially harmful behavior.

Other sources

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

— NVD

Affected Software

1 affected component
Openrobotics Robot Operating System=2-foxy

Event History

Jun 27, 2023
CVE Published
via MITRE·12:00 AM
Rejected
via MITRE·12:00 AM
Data Sourced
via NVD·06:15 PM
Description
May 27, 2024
Rejected
via MITRE·12:14 AM

Frequently Asked Questions

1

What is the severity of CVE-2023-33566?

CVE-2023-33566 is classified as a high severity vulnerability due to the potential for unauthorized node injection.

2

How do I fix CVE-2023-33566?

To fix CVE-2023-33566, update to a patched version of ROS2 Foxy that addresses this vulnerability.

3

What kind of attacks can be conducted using CVE-2023-33566?

Exploitation of CVE-2023-33566 allows an attacker to inject malicious ROS2 nodes, potentially disrupting system operations.

4

What systems are affected by CVE-2023-33566?

CVE-2023-33566 affects all versions of ROS2 Foxy Fitzroy where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3.

5

Is CVE-2023-33566 remotely exploitable?

Yes, CVE-2023-33566 can be exploited remotely by malicious users to inject unauthorized nodes into the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203