CVE-2024-39780 is a critical YAML deserialization vulnerability affecting the Robot Operating System (ROS) 'dynparam' tool in Noetic and earlier distributions. This flaw, stemming from the unsafe use of yaml.load() in 'set' and 'get' verbs, allows for arbitrary Python object creation and execution of arbitrary Python code by local or remote users. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
indigo_iglooCPE matchmatch criteria | cpe:2.3:o:openrobotics:robot_operating_system:indigo_igloo:*:*:*:*:*:*:* | ||
kinetic_kameCPE matchmatch criteria | cpe:2.3:o:openrobotics:robot_operating_system:kinetic_kame:*:*:*:*:*:*:* | ||
melodic_moreniaCPE matchmatch criteria | cpe:2.3:o:openrobotics:robot_operating_system:melodic_morenia:*:*:*:*:*:*:* | ||
noetic_ninjemysCPE matchmatch criteria | cpe:2.3:o:openrobotics:robot_operating_system:noetic_ninjemys:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.