Vulnerability Intelligence Report
Data Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Open DDS
CVE-2023-24012
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7_verify function used to validate S/MIME signatures.
No Active Exploit Signals
CVSS Base Score
8.2
HIGH
Exploitability:3.9
Impact Score:4.3
EPSS Probability:0.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-200 ↗CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| OpenDDS | DDS | all versions (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.271%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Spanish National Cybersecurity Institute, S.A. (INCIBE) · CERT · Spain |
| Reserved | 2023-01-20T12:00:57 |
| Published | 2025-01-09T14:36:15 |
| Patch Date | 2023-02-25 |
| Last Updated | 2025-01-09T20:05:44 |
Community Chatter & Buzz