PT-2019-15889 · Ros2 · Sros 2
Mikaelarguedas
+2
·
Published
2019-12-06
·
Updated
2019-12-13
·
CVE-2019-19625
CVSS v3.1
7.5
High
| Vector | AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
SROS 2 version 0.8.1
Description
The issue is related to a leaky default configuration, as indicated in the policy/defaults/dds/governance.xml document, which causes SROS 2 to leak node information. This leak is due to the default configuration used by SROS 2, which provides tools for generating and distributing keys for Robot Operating System 2 and utilizes the underlying security plugins of DDS from ROS 2.
Recommendations
For SROS 2 version 0.8.1, review and adjust the configuration settings in the policy/defaults/dds/governance.xml document to prevent node information leaks. Consider modifying the default configuration to enhance security and restrict unnecessary information disclosure.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sros 2