CVE-2024-39780

CVSS 3.1 Score 8.4 of 10 (high)

Details

Published Apr 2, 2025
CWE ID 502
CWE ID 20

Summary

CVE-2024-39780 is a new vulnerability affecting the Robot Operating System (ROS) 'dynparam' tool in ROS distributions Noetic and earlier. This command-line utility, used for getting, setting, and deleting parameters of a dynamically configurable node, contains a YAML deserialization flaw. The issue arises due to the implementation of yaml.load() function in the 'set' and 'get' verbs, which can result in the creation of arbitrary Python objects. Consequently, a local or remote user can exploit this vulnerability to execute arbitrary Python code. The latest version of ROS Noetic, with commit 3d93ac13603438323d7e9fa74e879e45c5fe2e8e, addresses this security weakness.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share