CVE-2023-46256

MEDIUM

PX4-Autopilot <1.14.0-rc1 - Buffer Overflow

Title source: llm
STIX 2.1

Description

PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index` value checking. A malfunction of the sensor device can cause a heap buffer overflow with leading unexpected drone behavior. Malicious applications can exploit the vulnerability even if device sensor malfunction does not occur. Up to the maximum value of an `unsigned int`, bytes sized data can be written to the heap memory area. As of time of publication, no fixed version is available.

Scores

CVSS v3 4.4
EPSS 0.0030
EPSS Percentile 53.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-122 CWE-120 CWE-787
Status published
Products (2)
dronecode/px4_drone_autopilot 1.14.0 beta1 (3 CPE variants)
dronecode/px4_drone_autopilot < 1.13.3
Published Oct 31, 2023
Tracked Since Feb 18, 2026