PT-2026-29340 · Unknown · Px4-Autopilot

Dolev Aviv

·

Publicado

2026-03-31

·

Atualizado

2026-04-15

·

CVE-2026-1579

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PX4 Autopilot (affected versions not specified)
Description The MAVLink communication protocol, as used by PX4 Autopilot, does not require cryptographic authentication by default. Without MAVLink 2.0 message signing enabled, unauthenticated parties with access to the MAVLink interface can send messages, including the SERIAL CONTROL message which provides interactive shell access. Enabling MAVLink 2.0 message signing in PX4 provides cryptographic authentication and rejects unsigned messages at the protocol level. The SERIAL CONTROL message allows for remote shell access.
Recommendations Enable MAVLink 2.0 message signing to provide cryptographic authentication for all MAVLink communication.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1579

Produtos afetados

Px4-Autopilot