CVE-2024-41644: Critical severity robot operating system (ros) vulnerability
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dynparamhandler component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41644?
CVE-2024-41644 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-41644?
To mitigate CVE-2024-41644, it is recommended to update to the latest version of Open Robotics Robot Operating System 2 ROS2 navigation2 that addresses the insecure permissions.
What components are affected by CVE-2024-41644?
CVE-2024-41644 specifically affects the dyn_param_handler_ component in Open Robotics Robot Operating System 2 ROS2 navigation2.
Can CVE-2024-41644 be exploited remotely?
Yes, CVE-2024-41644 can potentially be exploited remotely by attackers with access to the affected component.
Which versions of Open Robotics Robot Operating System are impacted by CVE-2024-41644?
CVE-2024-41644 impacts the Open Robotics Robot Operating System 2 ROS2 navigation2 versions humble and iron.