CVE-2023-24012 is a vulnerability affecting some DDS (Data Distribution Service) vendors due to a non-compliant implementation of permission document verification. The vulnerability arises from improper use of the OpenSSL PKCS7_verify function for validating S/MIME signatures in PKCS#7 certificates. Attackers can craft malicious DDS Participants or ROS 2 Nodes with valid certificates to bypass permission checks and gain unauthorized control over the secure DDS databus system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Dockerized proof-of-concept demonstrating an SROS2/DDS Security authorization bypass in ROS 2 Foxy by tampering with locally stored permissions and re-signing them. Structure: - Dockerfile: Builds a ROS 2 Foxy environment (tiryoh/ros2:foxy base) and installs build/security dependencies (openssl, libssl-dev, etc.), creates a world-writable /keystore directory, and copies in poc.sh. - README.md: Describes the scenario: a listener initially restricted to subscribing to 'something_else' can be made to subscribe to 'chatter' by modifying a signed permissions file. - poc.sh: Main PoC script. It (1) enables ROS security via environment variables (ROS_SECURITY_ENABLE=true, ROS_SECURITY_STRATEGY=Enforce, ROS_SECURITY_KEYSTORE=/keystore), (2) generates a keystore and keys for /talker and /listener using 'ros2 security', (3) writes policy.xml/node.xml/launch.xml to define allowed topics (talker publishes chatter; listener subscribes something_else), (4) runs ros2 launch to confirm listener cannot hear 'I heard:' output, (5) exploits the issue by editing /keystore/enclaves/listener/permissions.xml (sed replacing rt/something_else with rt/chatter) and re-signing permissions.p7s using the listener's own cert/key via 'openssl smime -sign', then (6) re-runs ros2 launch to show the listener now receives messages. Exploit capability: - Local policy/permission tampering leading to privilege escalation within ROS 2 topic access control (subscription authorization bypass). No remote network exploitation is implemented; the PoC assumes attacker access to the keystore files and signing material (or the ability to use the node's credentials) on the target system/container.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.