Víctor Mayoral Vilches

Results 57 issues of Víctor Mayoral Vilches

TCPROS is a transport layer for ROS Messages and Services. It uses standard TCP/IP sockets for transporting message data. Inbound connections are received via a TCP Server Socket with a...

new layer

Looks fantastic. Very well done guys. Is Gazebo integration planned anytime soon? Seems that this could add tons of value in top of ODE or Bullet. Thanks,

feature request

As @awesomebytes prototyped, it'll be interesting to simplify the process of adding new code by using an API. Refer to: - https://github.com/awesomebytes/blockly/blob/marco_version/generators/python/basic_ros.js#L30-L39 - https://github.com/awesomebytes/ros_rosimple/blob/marco_version/src/rosimple/ros_basic_api.py#L48-L49

```yaml id: 3316 title: 'RVD#3316: No authentication in MAVLink protocol' type: vulnerability description: The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization)...

severity: critical
components software
vulnerability
robot component: PX4
robot component: Ardupilot
robot component: MAVLink
version: 1.0

```yaml id: 449 title: 'RVD#449: Lack of Forward Secrecy (FS) support in handshake algorithms' type: weakness description: "In the DDS protocol, only two types of algorithms, \u201CDH+MODP-2048-256\u201D\ \ and \u201CECDH+prime256v1-CEUM\u201D,...

components software
vulnerability
robot component: ROS2
vendor: eProsima
vendor: RTI
vendor: ADLINK
robot component: DDS
triage

```yaml id: 451 title: 'RVD#451: DDS cryptographic plugin, AES_GCM subject to forgery, key recovery and timing attacks, and nonce replay attacks' type: vulnerability description: For the cryptographic plugin, AES_GCM and...

components software
vulnerability
robot component: ROS2
robot component: FastRTPS
vendor: eProsima
vendor: RTI
vendor: ADLINK
robot component: DDS
triage

```yaml id: 450 title: 'RVD#450: DDS authentication plugin weakness in prime256v1 curves might lead to data to side channel attacks' type: weakness description: For the authentication plug-in, a participant is...

components software
vulnerability
robot component: ROS2
robot component: FastRTPS
vendor: eProsima
vendor: RTI
vendor: ADLINK
robot component: DDS
triage

```yaml id: 453 title: 'RVD#453: Prediction number attacks on sequence number during RTPS initialization (affects authentication and access DDS security plugins)' type: weakness description: "The DDS Security standard states that,...

components software
vulnerability
robot component: ROS2
robot component: FastRTPS
vendor: eProsima
vendor: RTI
vendor: ADLINK
robot component: DDS
CWE-340
triage

```yaml id: 3317 title: 'RVD#3317: MAVLink version handshaking allows for an attacker to bypass authentication' type: vulnerability description: The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its...

components software
vulnerability
severity: high
robot component: PX4
robot component: Ardupilot
robot component: MAVLink
version: 1.0
version: 2.0

```yaml { "id": 673, "title": "RVD#673: CB3.1 3.4.5-3.14.x listen and execution of arbitrary URScript code", "type": "vulnerability", "description": "In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports...

severity: critical
vulnerability
vendor: Universal Robots
robot: UR3
robot: UR5
robot: UR10
robot component: Universal Robots Controller
Universal Robots