U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-30696

Change History

CVE Translated by MITRE 5/26/2024 9:15:17 PM

Action Type Old Value New Value
Removed Translation
Title: ROS2 Galactic Geochelone
Description: Vulnerabilidad de inyección de comandos del sistema operativo en ROS2 Galactic Geochelone en ROS_VERSION 2 y ROS_PYTHON_VERSION 3, permite a atacantes remotos ejecutar código arbitrario, escalar privilegios y obtener información confidencial a través del procesamiento de comandos o componentes de llamadas al sistema en ROS2, incluidos módulos de ejecución de comandos externos, controladores de llamadas del sistema y scripts de interfaz. NOTA: esto es cuestionado por varios terceros que creen que no había pruebas razonables para determinar la existencia de una vulnerabilidad.

								
						

CVE Rejected by MITRE 5/26/2024 9:15:17 PM

Action Type Old Value New Value

CVE Modified by MITRE 5/26/2024 9:15:17 PM

Action Type Old Value New Value
Changed Description
OS command injection vulnerability in ROS2 Galactic Geochelone in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the command processing or system call components in ROS2, including External Command Execution Modules, System Call Handlers, and Interface Scripts. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/2

								
						
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/3

								
						
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/4

								
						
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/5

								
						
Removed Reference
MITRE https://github.com/yashpatelphd/CVE-2024-30696

								
						
Removed Tag
MITRE disputed