PT-2023-15617 · Ros · Tf Remapper Node
Published
2023-01-04
·
Updated
2024-08-03
·
CVE-2022-48217
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
tf remapper node component version 1.1.1 for Robot Operating System (ROS)
Description
The issue allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled
old tf topic name and/or new tf topic name parameter. The vendor's position is that it is the responsibility of the programmer to ensure only known and required parameters are set and unexpected parameters are not.Recommendations
For tf remapper node component version 1.1.1, as a temporary workaround, consider restricting the use of the
old tf topic name and new tf topic name parameters until a patch is available. Ensure that only known and required parameters are set and unexpected parameters are not, following the vendor's guidance on secure programming practices. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tf Remapper Node