SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_kind configuration. (SROS2 provides the tools to generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2.)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/aliasrobotics/RVD/issues/922 | third party advisory exploit |
https://github.com/ros2/sros2/issues/172 | third party advisory |
https://asciinema.org/a/yuGkBlaPC33wqL4qABRlgxBkd | third party advisory |
https://ros-swg.github.io/ROSCon19_Security_Workshop/ | vendor advisory |
https://github.com/ros-swg/turtlebot3_demo | third party advisory |