CVE-2022-48198

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/01/2023
Last modified:
11/04/2025

Description

The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled time_ref_topic parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ntpd_driver_project:ntpd_driver:*:*:*:*:*:*:*:* 1.3.0 (excluding)
cpe:2.3:a:ntpd_driver_project:ntpd_driver:*:*:*:*:*:*:*:* 2.0.0 (including) 2.2.0 (excluding)
cpe:2.3:o:openrobotics:robot_operating_system:-:*:*:*:*:*:*:*