CVE-2024-24255: Race Condition
Published Feb 6, 2024
·Updated
A Race Condition discovered in geofence.cpp and missionfeasibilitychecker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions.
Affected Software
1 affected component
Dronecode Px4 Drone Autopilot<=1.14.0
Event History
Feb 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24255?
CVE-2024-24255 is considered a critical vulnerability due to its potential to enable attackers to manipulate drone missions.
2
How do I fix CVE-2024-24255?
To fix CVE-2024-24255, update your PX4 Autopilot software to version 1.14.1 or later.
3
What systems are affected by CVE-2024-24255?
CVE-2024-24255 affects PX4 Autopilot versions 1.14 and earlier.
4
What is a race condition in the context of CVE-2024-24255?
In the context of CVE-2024-24255, a race condition allows an attacker to exploit timing flaws in the software to send drones on unintended missions.
5
Can CVE-2024-24255 lead to physical damage?
Yes, CVE-2024-24255 can lead to physical damage or loss of control over drones, posing safety risks.