NA

CVE-2024-30723

Published: 10/04/2024 Updated: 14/05/2024

Vulnerability Summary

An unauthorized node injection vulnerability has been identified in ROS Kinetic Kame in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows remote malicious users to escalate privileges and inject malicious ROS nodes into the system due to insecure permissions. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability.

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: 83 bogus CVEs assigned to Robot Operating System (ROS) <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Yash P ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: 83 bogus CVEs assigned to Robot Operating System (ROS) <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Mark E ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: 83 bogus CVEs assigned to Robot Operating System (ROS) <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Yash P ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> 83 bogus CVEs assigned to Robot Operating System (ROS) <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Mark Esler ...

Github Repositories

Unauthorized Node Injection Vulnerability in ROS Kinetic Kame

CVE ID CVE-2024-30723 Title Unauthorized Node Injection Vulnerability in ROS Kinetic Kame Vulnerability Type Injection Severity TBD Vendor The Open Source Robotics Foundation (OSRF) Products Affected ROS Kinetic Kame (ROS_VERSION=1 and ROS_PYTHON_VERSION=3) Description An unauthorized node injection vulnerability has been identified in ROS Kinetic Kame versions where ROS_VERSIO