Description
Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute
In plain language
AI Worth attentionCVE-2024-40427 is a crash-and-control bug in PX4 drone autopilot that can let someone run commands and make the autopilot stop, so you should update if you operate drones using PX4 (especially if anyone can reach it).
CVE-2024-40427 is a stack buffer overflow in PX4-Autopilot (CWE-120) that can enable command execution and lead to denial of service, with a low authentication requirement and local attack vector.
What to do now
- Check which PX4-Autopilot version your drone systems are running (and whether that build includes the vulnerable code referenced for CVE-2024-40427).
- If you are running PX4-Autopilot v1.14.3, update PX4-Autopilot to the fixed state using the vendor’s provided commit.
- After upgrading, verify your autopilot boots and performs normal mission start/arming checks, then test your specific flight workflow in a safe environment.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:CScopeC:NConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-40427 and every CVE in our database. Create a free account — no credit card required.
Create Free Account