RVD
RVD copied to clipboard
RVD#99: ROS 2 Goal topic vulnerable to DoS attacks.
{
"id": 99,
"title": "RVD#99: ROS 2 Goal topic vulnerable to DoS attacks.",
"type": "vulnerability",
"description": "The ROS 2 nodes that control the motor fail when a big number of messages are sent in a small span of time. The application crashes and is not able to recover from failure, causing a DoS. This is probably caused by memory leaks, bugs or log storage.",
"cwe": "CWE-Denial of Service (CWE-400)",
"cve": "None",
"keywords": [
"malformed",
"robot",
"robot: MARA",
"severity: medium",
"vendor: Acutronic Robotics",
"vulnerability"
],
"system": "MARA",
"vendor": "Acutronic Robotics",
"severity": {
"rvss-score": 5.5,
"rvss-vector": "RVSS:1.0/AV:IN/AC:L/PR:N/UI:N/Y:Z/S:U/C:N/I:N/A:H/H:U",
"severity-description": "medium",
"cvss-score": 7.5,
"cvss-vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
"links": [
"https://github.com/aliasrobotics/RVD/issues/99"
],
"flaw": {
"phase": "unknown",
"specificity": "N/A",
"architectural-location": "N/A",
"application": "N/A",
"subsystem": "N/A",
"package": "N/A",
"languages": "None",
"date-detected": "2019-02-10",
"detected-by": "",
"detected-by-method": "N/A",
"date-reported": "2019-02-10",
"reported-by": "",
"reported-by-relationship": "N/A",
"issue": "https://github.com/aliasrobotics/RVD/issues/99",
"reproducibility": "",
"trace": null,
"reproduction": "",
"reproduction-image": ""
},
"exploitation": {
"description": "",
"exploitation-image": "",
"exploitation-vector": ""
},
"mitigation": {
"description": "",
"pull-request": "",
"date-mitigation": null
}
}
Feedback (automatically generated):
-
FIXME: Flaw not identified as a vulnerability, weakness or exposure. Have you included
# Vulnerability (or Weakness or Exposure) reportat the top of the ticket?, seefor more information or review other tickets to get inspiration
Please review the feedback above. Once addressed, either request the removal of the malformed label to trigger another automatic review.
Feedback (automatically generated):
-
FIXME:
RobotorRobot componentnot present in summary table or invalid, seefor more information or review other tickets and get inspiration
Please review the feedback above. Once addressed, either request the removal of the malformed label to trigger another automatic review.