PT-2021-21529 · Open Robotics · Ros Noetic+2

Junfeng Yang

·

Published

2021-09-21

·

Updated

2021-10-06

·

CVE-2021-37146

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ROS Melodic versions 1.4.11 and earlier ROS Noetic versions 1.15.11 and earlier
Description The issue is related to an infinite loop in the Open Robotics ros comm XMLRPC server, which allows remote attackers to cause a Denial of Service in ros comm via a crafted XMLRPC call.
Recommendations For ROS Melodic version 1.4.11 and earlier, update to a version later than 1.4.11 to resolve the issue. For ROS Noetic version 1.15.11 and earlier, update to a version later than 1.15.11 to resolve the issue.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37146

Affected Products

Ros Melodic
Ros Noetic
Ros Comm