// For flags

CVE-2022-48198

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled time_ref_topic parameter.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-01-01 CVE Reserved
  • 2023-01-01 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ntpd Driver Project
Search vendor "Ntpd Driver Project"
Ntpd Driver
Search vendor "Ntpd Driver Project" for product "Ntpd Driver"
< 1.3.0
Search vendor "Ntpd Driver Project" for product "Ntpd Driver" and version " < 1.3.0"
-
Affected
in Openrobotics
Search vendor "Openrobotics"
Robot Operating System
Search vendor "Openrobotics" for product "Robot Operating System"
--
Safe
Ntpd Driver Project
Search vendor "Ntpd Driver Project"
Ntpd Driver
Search vendor "Ntpd Driver Project" for product "Ntpd Driver"
>= 2.0.0 < 2.2.0
Search vendor "Ntpd Driver Project" for product "Ntpd Driver" and version " >= 2.0.0 < 2.2.0"
-
Affected
in Openrobotics
Search vendor "Openrobotics"
Robot Operating System
Search vendor "Openrobotics" for product "Robot Operating System"
--
Safe