CVE-2023-24012 Details
Description
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7_verify function used to validate S/MIME signatures.
A vulnerability exists in certain Data Distribution Service (DDS) implementations, including OpenDDS and ROS 2, due to improper validation of PKCS#7 certificates. This flaw allows an attacker to create malicious DDS participants or ROS 2 nodes with valid certificates, potentially compromising the security of the DDS databus system. The issue arises from a non-compliant implementation of permission document verification by some DDS vendors, specifically related to the incorrect use of the OpenSSL PKCS7_verify function for validating S/MIME signatures.
To address this vulnerability, separate the roles of Identity CA and Permissions CA into different certificates. This change will prevent malicious nodes from exploiting the certificate validation process to gain unauthorized control over the DDS databus system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 9, 2025CISA-ADP
Assessed Jan 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/vmayoral/235c02d0b0ef85a29812eff6980ff80d | CISA-ADP | ExploitTechnical Description |
| https://gist.github.com/vmayoral/235c02d0b0ef85a29812eff6980ff80d | [email protected] | ExploitTechnical Description |
| https://github.com/ros2/sros2/issues/282 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Data Distribution Service | All versions |
CPE
Remediation
| |
| ROS 2 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 9, 2025 | CVE Modified | CISA-ADP |
| Jan 9, 2025 | New CVE Received | [email protected] |
Volerion