CVE-2023-33566: Critical severity robot operating system (ros) vulnerability
An unauthorized node injection vulnerability has been identified in ROS2 Foxy Fitzroy versions where ROSVERSION is 2 and ROSPYTHONVERSION is 3. This vulnerability could allow a malicious user to inject malicious ROS2 nodes into the system remotely. Once injected, these nodes could disrupt the normal operations of the system or cause other potentially harmful behavior.
Other sources
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33566?
CVE-2023-33566 is classified as a high severity vulnerability due to the potential for unauthorized node injection.
How do I fix CVE-2023-33566?
To fix CVE-2023-33566, update to a patched version of ROS2 Foxy that addresses this vulnerability.
What kind of attacks can be conducted using CVE-2023-33566?
Exploitation of CVE-2023-33566 allows an attacker to inject malicious ROS2 nodes, potentially disrupting system operations.
What systems are affected by CVE-2023-33566?
CVE-2023-33566 affects all versions of ROS2 Foxy Fitzroy where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3.
Is CVE-2023-33566 remotely exploitable?
Yes, CVE-2023-33566 can be exploited remotely by malicious users to inject unauthorized nodes into the system.