Описание
PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and mission_feasibility_checker.cpp. This will result in the drone uploading overlapping geofences and mission routes.
Ссылки
- ExploitThird Party Advisory
- Product
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 1.14.0 (включая)
cpe:2.3:a:dronecode:px4_drone_autopilot:*:*:*:*:*:*:*:*
EPSS
Процентиль: 11%
0.00037
Низкий
4.2 Medium
CVSS3
Дефекты
CWE-362
CWE-362
Связанные уязвимости
CVSS3: 4.2
github
около 2 лет назад
PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and mission_feasibility_checker.cpp. This will result in the drone uploading overlapping geofences and mission routes.
EPSS
Процентиль: 11%
0.00037
Низкий
4.2 Medium
CVSS3
Дефекты
CWE-362
CWE-362