Lucene search

K
cveGitHub_MCVE-2023-46256
HistoryOct 31, 2023 - 4:15 p.m.

CVE-2023-46256

2023-10-3116:15:10
CWE-787
CWE-120
CWE-122
GitHub_M
web.nvd.nist.gov
22
px4-autopilot
drone
heap buffer overflow
vulnerability
parser function
sensor device
malicious applications
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.001

Percentile

50.1%

PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of parserbuf_index value checking. A malfunction of the sensor device can cause a heap buffer overflow with leading unexpected drone behavior. Malicious applications can exploit the vulnerability even if device sensor malfunction does not occur. Up to the maximum value of an unsigned int, bytes sized data can be written to the heap memory area. As of time of publication, no fixed version is available.

Affected configurations

Nvd
Vulners
Node
dronecodepx4_drone_autopilotRange1.13.3
OR
dronecodepx4_drone_autopilotMatch1.14.0beta1
OR
dronecodepx4_drone_autopilotMatch1.14.0beta2
OR
dronecodepx4_drone_autopilotMatch1.14.0rc1
VendorProductVersionCPE
dronecodepx4_drone_autopilot*cpe:2.3:a:dronecode:px4_drone_autopilot:*:*:*:*:*:*:*:*
dronecodepx4_drone_autopilot1.14.0cpe:2.3:a:dronecode:px4_drone_autopilot:1.14.0:beta1:*:*:*:*:*:*
dronecodepx4_drone_autopilot1.14.0cpe:2.3:a:dronecode:px4_drone_autopilot:1.14.0:beta2:*:*:*:*:*:*
dronecodepx4_drone_autopilot1.14.0cpe:2.3:a:dronecode:px4_drone_autopilot:1.14.0:rc1:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "PX4",
    "product": "PX4-Autopilot",
    "versions": [
      {
        "version": "<= 1.14.0-rc1",
        "status": "affected"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.001

Percentile

50.1%

Related for CVE-2023-46256