漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
TIER IV Nebula 1.2.0 Heap Out-of-Bounds Read via VLP32 UDP Decoder
Vulnerability Description
TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. Attackers can send a malformed datagram to the Velodyne UDP sensor port, which lacks sender-address restrictions present in other drivers, causing fabricated points derived from heap memory contents to be silently published into downstream PointCloud2 messages consumed by Autoware nodes.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
跨界内存读
Vulnerability Title
TIER IV Nebula 缓冲区错误漏洞
Vulnerability Description
TIER IV Nebula是日本TIER IV公司的一款工业互联网企业应用软件。 TIER IV Nebula 1.2.0及之前版本存在缓冲区错误漏洞,该漏洞源于Vlp32Decoder::unpack()函数存在越界读取,可能导致未经身份验证的远程攻击者通过发送短UDP数据报使解码器越界读取堆内存,并将伪造数据发布到下游PointCloud2消息中。
CVSS Information
N/A
Vulnerability Type
N/A