Vulnerability Details CVE-2022-48198
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled time_ref_topic parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-48198
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:-
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:1.0.0
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:1.0.1
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:1.0.2
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:1.1.0
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:1.1.1
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:1.2.0
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:2.0.0
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:2.0.1
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:2.0.2
-
cpe:2.3:a:ntpd_driver_project:ntpd_driver:2.1.0
-
cpe:2.3:o:openrobotics:robot_operating_system:-