01 Record
CVE-2024-42002
Unsafe use of eval() method in ros2 topic hz tool
HighPUBLISHEDCNA: canonical
CNA base score8.6 CVSS v4.0CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
02 Description
Unsafe use of eval() method in ros2 topic hz tool
03 Exploitation and scoring
- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- Not scored by EPSS
- EPSS percentile
- Not scored by EPSS
- NVD base score
- The NVD has published no score for this record
- NVD CVSS vector
- No NVD score to derive
- NVD analysis status
- Not recorded
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
04 Metadata
- Published
- 2026-09-28 21:38Z1 HR AGO
- Last updated
- 2026-09-28 21:38Z1 HR AGO
- Reserved
- 2024-08-01
- Assigning CNA
- canonical
- Record state
- PUBLISHED
- Severity
- High (CVSS 8.6)
- CNA CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- Weaknesses
- Data version
- 5.2
- Document digest
- f94fe24b10c2a725a96f22107496ca50cb7131be98958b028b42e2ade9dc4909
05 Affected products
VendorProductVersionsPlatforms
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Rolling Ridley, Lyrical Luth, Kilted Kaiju, Jazzy Jalisco, Iron Irwini, Humble Hawksbill, Galactic Geochelone, Foxy Fitzroy, Eloquent Elusor, Dashing Diademata, Crystal ClemmysLinux, MacOS, Windows
06 References
07 Remediation
No fixed release is available at the time of publication. A fix is proposed upstream in https://github.com/ros2/ros2cli/pull/1001.