Security Flaw in DDS Systems by Various Vendors
CVE-2023-24011
What is CVE-2023-24011?
An attacker may exploit a vulnerability in DDS systems by manipulating malicious DDS Participants or ROS 2 Nodes equipped with legitimate certificates. This flaw arises from a non-compliant implementation of permission document verification, particularly through an improper use of the OpenSSL PKCS7_verify function. The result is a compromised secure DDS databus system, granting full control to the attacker. This issue emphasizes the need for rigorous validation measures in the configuration of PKCS#7 certificates to safeguard against unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DDS all versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
