The ntpd_driver component before 1.3.0 and 2.x before 2.2...
Critical severity
Unreviewed
Published
Jan 1, 2023
to the GitHub Advisory Database
•
Updated Apr 11, 2025
Description
Published by the National Vulnerability Database
Jan 1, 2023
Published to the GitHub Advisory Database
Jan 1, 2023
Last updated
Apr 11, 2025
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled time_ref_topic parameter.
References