synced 7 MIN AGO
01 Record

CVE-2024-42002

Unsafe use of eval() method in ros2 topic hz tool

HighPUBLISHEDCNA: canonical
CNA base score8.6 CVSS v4.0CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

02 Description

Unsafe use of eval() method in ros2 topic hz tool

03 Exploitation and scoring

Exploitation
Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
SSVC decision
Not assessed by CISA
EPSS probability
Not scored by EPSS
EPSS percentile
Not scored by EPSS
NVD base score
The NVD has published no score for this record
NVD CVSS vector
No NVD score to derive
NVD analysis status
Not recorded
Red Hat severity
No Red Hat rating. Red Hat rates the CVEs that affect its products.

Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.

04 Metadata

Published
2026-09-28 21:38Z1 HR AGO
Last updated
2026-09-28 21:38Z1 HR AGO
Reserved
2024-08-01
Assigning CNA
canonical
Record state
PUBLISHED
Severity
High (CVSS 8.6)
CNA CVSS vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Weaknesses
  • CWE-94Improper Control of Generation of Code ('Code Injection')Base
  • CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')Variant
Data version
5.2
Document digest
f94fe24b10c2a725a96f22107496ca50cb7131be98958b028b42e2ade9dc4909

05 Affected products

VendorProductVersionsPlatforms
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Rolling Ridley, Lyrical Luth, Kilted Kaiju, Jazzy Jalisco, Iron Irwini, Humble Hawksbill, Galactic Geochelone, Foxy Fitzroy, Eloquent Elusor, Dashing Diademata, Crystal ClemmysLinux, MacOS, Windows

06 References

07 Remediation

No fixed release is available at the time of publication. A fix is proposed upstream in https://github.com/ros2/ros2cli/pull/1001.