PT-2023-30521 · Px4 · Px4

Pwn9Uin

·

Publicado

2023-11-13

·

Atualizado

2023-11-20

·

CVE-2023-47625

CVSS v3.1

2.9

Baixa

VetorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions PX4 autopilot versions prior to 1.14.0
Description A global buffer overflow vulnerability exists in the CrsfParser TryParseCrsfPacket function due to an invalid size check. This allows a malicious user to create an RC packet remotely, which can trigger the buffer overflow and cause the drone to behave unexpectedly.
Recommendations For versions prior to 1.14.0, upgrade to version 1.14.0 to resolve the issue. As a temporary workaround, consider restricting access to the CrsfParser TryParseCrsfPacket function until the upgrade is applied.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-47625
GHSA-QPW7-65WW-WJ82

Produtos afetados

Px4