CVE-2024-41646: Critical severity robot operating system (ros) vulnerability
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2dwbcontroller.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41646?
CVE-2024-41646 is classified as a high-severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-41646?
To fix CVE-2024-41646, ensure that the permissions for the nav2_dwb_controller are properly configured to restrict unauthorized access.
What software versions are affected by CVE-2024-41646?
CVE-2024-41646 affects Open Robotics Robot Operating System 2 versions 2-humble and 2-iron.
What type of attack does CVE-2024-41646 enable?
CVE-2024-41646 allows an attacker to execute arbitrary code through a crafted script sent to the nav2_dwb_controller.
Is there a workaround for CVE-2024-41646?
A potential workaround for CVE-2024-41646 is to restrict script execution permissions until a patch can be applied.