<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – ROS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ros.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ros-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – ROS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:49 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-41551 – A vulnerability has been identified in ROS# (All versions &lt; V2.2.2). Affected ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41551</guid>
    <pubDate>Tue, 12 May 2026 10:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41551</strong></p>
  <p>A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user input is not properly sanitized. This could allow a remote attacker to access arbitrary files on the device.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26011 – navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26011</guid>
    <pubDate>Thu, 12 Feb 2026 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26011</strong></p>
  <p>navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering logic. By publishing a single crafted geometry_msgs/PoseWithCovarianceStamped message with extreme covariance values to the /initialpose topic, an unauthenticated attacker on the same ROS 2 DDS domain can trigger a negati…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41110 – Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41110</guid>
    <pubDate>Wed, 22 Oct 2025 09:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41110</strong></p>
  <p>Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the robot's WiFi and view all its data, as it runs on ROS 2 without default authentication. In addition, the attacker can connect via SSH and gain full control of the robot, which could cause physical damage to the robot itself or its environment.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3753 – A code execution vulnerability has been identified in the Robot Operating System...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3753</guid>
    <pubDate>Thu, 17 Jul 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3753</strong></p>
  <p>A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() function to process unsanitized, user-supplied input in the 'rosbag filter' command. This flaw enables attackers to craft and execute arbitrary Python code.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41921 – A code injection vulnerability has been discovered in the Robot Operating System...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41921</guid>
    <pubDate>Thu, 17 Jul 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41921</strong></p>
  <p>A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability lies in the 'echo' verb, which allows a user to introspect a ROS topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sani…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41148 – A code injection vulnerability has been discovered in the Robot Operating System...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41148</guid>
    <pubDate>Thu, 17 Jul 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41148</strong></p>
  <p>A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitiz…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39835 – A code injection vulnerability has been identified in the Robot Operating System...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39835</guid>
    <pubDate>Thu, 17 Jul 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39835</strong></p>
  <p>A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() method to process user-supplied, unsanitized parameter values within the substitution args mechanism, which roslaunch evaluates before launching a node. This flaw allows at…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39289 – A code execution vulnerability has been discovered in the Robot Operating System...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39289</guid>
    <pubDate>Thu, 17 Jul 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39289</strong></p>
  <p>A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability stems from the use of the eval() function to process unsanitized, user-supplied parameter values via special converters for angle representations in radians. This flaw allowed attackers to craft and execute arbitrary Pyt…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39780 – A YAML deserialization vulnerability was found in the Robot Operating System (RO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39780</guid>
    <pubDate>Wed, 02 Apr 2025 08:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39780</strong></p>
  <p>A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of the yaml.load() function in the 'set' and 'get' verbs, and allows for the creation of arbitrary Python objects. Through…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24012 – An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24012</guid>
    <pubDate>Thu, 09 Jan 2025 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24012</strong></p>
  <p>An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24011 – An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24011</guid>
    <pubDate>Thu, 09 Jan 2025 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24011</strong></p>
  <p>An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24010 – An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24010</guid>
    <pubDate>Thu, 09 Jan 2025 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24010</strong></p>
  <p>An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48217 – The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48217</guid>
    <pubDate>Wed, 04 Jan 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48217</strong></p>
  <p>The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled old_tf_topic_name and/or new_tf_topic_name parameter. NOTE: the vendor's position is "it is the responsibility of the programmer to make…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-75</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-48198 – The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48198</guid>
    <pubDate>Sun, 01 Jan 2023 07:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-48198</strong></p>
  <p>The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled time_ref_topic parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37146 – An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37146</guid>
    <pubDate>Tue, 28 Sep 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37146</strong></p>
  <p>An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_comm via a crafted XMLRPC call.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-16124 – Integer Overflow or Wraparound vulnerability in the XML RPC library of OpenRobot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16124</guid>
    <pubDate>Tue, 13 Oct 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-16124</strong></p>
  <p>Integer Overflow or Wraparound vulnerability in the XML RPC library of OpenRobotics ros_comm communications packages allows unauthenticated network traffic to cause unexpected behavior. This issue affects: OpenRobotics ros_comm communications packages Noetic and prior versions. Fixed in https://github.com/ros/ros_comm/pull/2065.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10289 – Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw its...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10289</guid>
    <pubDate>Thu, 20 Aug 2020 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10289</strong></p>
  <p>Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creation of Python objects. Through this flaw in the ROS core package of actionlib, an attacker with local or remote access can make the ROS Master, execute arbitrary code in Python fo…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-10272 – MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10272</guid>
    <pubDate>Wed, 24 Jun 2020 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-10272</strong></p>
  <p>MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and CVE-2020-10271, this flaw allows malicious actors to command the robot at desire.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-10271 – MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10271</guid>
    <pubDate>Wed, 24 Jun 2020 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-10271</strong></p>
  <p>MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is the result of a bad set up and can be mitigated by appropriately configuring ROS and/or applying custom patches as appropriate. Currently, the ROS computational graph can be accessed fully from the wired exposed ports. In…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13465 – An issue was discovered in the ROS communications-related packages (aka ros_comm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13465</guid>
    <pubDate>Mon, 30 Dec 2019 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13465</strong></p>
  <p>An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. ROS_ASSERT_MSG only works when ROS_ASSERT_ENABLED is defined. This leads to a problem in the remove() function in clients/roscpp/src/libros/spinner.cpp. When ROS_ASSERT_ENABLED is not defined, the iterator loop will run out of the scope of the array, and cause denial of servic…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-13445 – An issue was discovered in the ROS communications-related packages (aka ros_comm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13445</guid>
    <pubDate>Mon, 30 Dec 2019 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-13445</strong></p>
  <p>An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. parseOptions() in tools/rosbag/src/record.cpp has an integer overflow when a crafted split option can be entered on the command line.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-13566 – An issue was discovered in the ROS communications-related packages (aka ros_comm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13566</guid>
    <pubDate>Fri, 22 Nov 2019 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-13566</strong></p>
  <p>An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. A buffer overflow allows attackers to cause a denial of service and possibly execute arbitrary code via an IP address with a long hostname.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10681 – roslib-socketio - The standard ROS Javascript Library fork for add support to so...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10681</guid>
    <pubDate>Tue, 29 May 2018 20:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10681</strong></p>
  <p>roslib-socketio - The standard ROS Javascript Library fork for add support to socket.io roslib-socketio downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote s…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9347 – In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9347</guid>
    <pubDate>Fri, 02 Jun 2017 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9347</strong></p>
  <p>In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-1966 – The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1966</guid>
    <pubDate>Mon, 24 Feb 2014 04:48:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-1966</strong></p>
  <p>The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (device outage) via crafted packets.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-6926 – The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6926</guid>
    <pubDate>Tue, 17 Dec 2013 04:46:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-6926</strong></p>
  <p>The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-6925 – The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6925</guid>
    <pubDate>Tue, 17 Dec 2013 04:46:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-6925</strong></p>
  <p>The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-2441 – RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2441</guid>
    <pubDate>Sat, 28 Apr 2012 00:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-2441</strong></p>
  <p>RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH or (2) HTTPS session, a different vulnerability than CVE-2012-1803.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-1803 – RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1803</guid>
    <pubDate>Sat, 28 Apr 2012 00:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-1803</strong></p>
  <p>RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1803">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
