-
Notifications
You must be signed in to change notification settings - Fork 33
Open
Labels
components softwareVulnerabilities in purely software robot components (e.g. a the ROS navigation stack)Vulnerabilities in purely software robot components (e.g. a the ROS navigation stack)robot component: ROSROS-related vulnerabilities.ROS-related vulnerabilities.robot: Raven 2severity: critical9.0 - 10.09.0 - 10.0vendor: Applied Dexterityvulnerability
Description
{
"id": 5,
"title": "RVD#5: ROS vulnerability affecting Raven 2 Robot: Denial of Service",
"type": "vulnerability",
"description": " Improper message verification in Applied Dexterity's Raven 2 could allow man-in-the-middle attackers cause a Denial-of-Service situation by sending out of safety-range commands and triggering the safety stop mechanism via spoofed network traffic. Credits to: Tamara Bonaci, Jeffrey Herron, Tariq Yusuf, Junjie Yan, Tadayoshi Kohno, Howard Jay Chizeck from the University of Washington",
"cwe": "CWE-Denial of Service (CWE-400)",
"cve": "None",
"keywords": [
"components software",
"robot component: ROS",
"severity: critical",
"vulnerability"
],
"system": "ROS",
"vendor": "N/A",
"severity": {
"rvss-score": 10.0,
"rvss-vector": "RVSS:1.0/AV:RN/AC:L/PR:N/UI:N/Y:Z/S:U/C:L/I:H/A:H/H:H",
"severity-description": "critical",
"cvss-score": 9.4,
"cvss-vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"
},
"links": [
"https://github.com/aliasrobotics/RVD/issues/5"
],
"flaw": {
"phase": "unknown",
"specificity": "N/A",
"architectural-location": "N/A",
"application": "N/A",
"subsystem": "N/A",
"package": "N/A",
"languages": "None",
"date-detected": "2015-05-13",
"detected-by": "",
"detected-by-method": "N/A",
"date-reported": "2015-05-13",
"reported-by": "",
"reported-by-relationship": "N/A",
"issue": "https://github.com/aliasrobotics/RVD/issues/5",
"reproducibility": "",
"trace": null,
"reproduction": "",
"reproduction-image": ""
},
"exploitation": {
"description": "",
"exploitation-image": "",
"exploitation-vector": ""
},
"mitigation": {
"description": "",
"pull-request": "",
"date-mitigation": ""
}
}Metadata
Metadata
Assignees
Labels
components softwareVulnerabilities in purely software robot components (e.g. a the ROS navigation stack)Vulnerabilities in purely software robot components (e.g. a the ROS navigation stack)robot component: ROSROS-related vulnerabilities.ROS-related vulnerabilities.robot: Raven 2severity: critical9.0 - 10.09.0 - 10.0vendor: Applied Dexterityvulnerability