PT-2026-29340 · Unknown · Px4-Autopilot
Dolev Aviv
·
Publicado
2026-03-31
·
Atualizado
2026-04-15
·
CVE-2026-1579
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PX4 Autopilot (affected versions not specified)
Description
The MAVLink communication protocol, as used by PX4 Autopilot, does not require cryptographic authentication by default. Without MAVLink 2.0 message signing enabled, unauthenticated parties with access to the MAVLink interface can send messages, including the
SERIAL CONTROL message which provides interactive shell access. Enabling MAVLink 2.0 message signing in PX4 provides cryptographic authentication and rejects unsigned messages at the protocol level. The SERIAL CONTROL message allows for remote shell access.Recommendations
Enable MAVLink 2.0 message signing to provide cryptographic authentication for all MAVLink communication.
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Px4-Autopilot