← Back

CVE-2024-39289

nvd nist
Published: Jul 17, 2025Modified: Aug 26, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: security@ubuntu.com (Secondary)

Description

A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability stems from the use of the eval() function to process unsanitized, user-supplied parameter values via special converters for angle representations in radians. This flaw allowed attackers to craft and execute arbitrary Python code.

Affected (4)

1 product
Robot Operating System
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Openrobotics
Version indigo_igloo
Version kinetic_kame
Version melodic_morenia
Version noetic_ninjemys

References (1)

Source: security@ubuntu.com
Product

Timeline

No history available yet.