PT-2023-30521 · Px4 · Px4
Pwn9Uin
·
Published
2023-11-13
·
Updated
2023-11-20
·
CVE-2023-47625
CVSS v3.1
2.9
Low
| Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
PX4 autopilot versions prior to 1.14.0
Description
A global buffer overflow vulnerability exists in the
CrsfParser TryParseCrsfPacket function due to an invalid size check. This allows a malicious user to create an RC packet remotely, which can trigger the buffer overflow and cause the drone to behave unexpectedly.Recommendations
For versions prior to 1.14.0, upgrade to version 1.14.0 to resolve the issue. As a temporary workaround, consider restricting access to the
CrsfParser TryParseCrsfPacket function until the upgrade is applied.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Px4