7.5

CVE-2019-19627

Exploit
SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_kind configuration. (SROS2 provides the tools to generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2.)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RosSros2 Version0.8.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.15% 0.797
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
cve@mitre.org 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://github.com/aliasrobotics/RVD/issues/922
Third Party Advisory
Exploit
https://asciinema.org/a/yuGkBlaPC33wqL4qABRlgxBkd
Third Party Advisory
https://github.com/ros-swg/turtlebot3_demo
Third Party Advisory
https://github.com/ros2/sros2/issues/172
Third Party Advisory
https://ros-swg.github.io/ROSCon19_Security_Workshop/
Vendor Advisory