Three CVEs in a widely deployed ground control station.
Coordinated disclosure complete. Patches available. Details of the chain, now that operators have had time to update.
Three vulnerabilities we reported ninety days ago have been fixed and assigned identifiers. All three are in the same ground control station, and chained they take an attacker on the operator network to arbitrary command execution on the host.
- An unauthenticated local service used for plugin discovery.
- A path traversal in mission file import.
- A privileged helper that accepted commands from any local process.
The vendor responded within four days and shipped a fix in six weeks. That is a good outcome and worth saying out loud — coordinated disclosure works when the vendor engages.
Operators should confirm they are on the current release. If you run this software on a shared laptop in a vehicle, this is the week to check.
ASEC