CVE-2020-16124 is an Integer Overflow or Wraparound vulnerability within the XML RPC library of OpenRobotics ros_comm communications packages, impacting Noetic and prior versions. This critical vulnerability (CVSS 9.8) allows unauthenticated network traffic to cause unexpected behavior, with potential for high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 80/100 indicates significant theoretical risk. The issue has been addressed in a patch available on GitHub.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.15.9CPE matchmatch criteria | cpe:2.3:a:ros:ros-comm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.