Impact
The vulnerability resides in the EGOReplanFSM component of ZJU-FAST-Lab EGO-Planner-v2 and allows an attacker to trigger a crash or persistent failure in the planning module, leading to a loss of service availability for the affected system. The weakness enables the attacker to cause the application to become unresponsive or terminate, effectively denying legitimate users access. The impact is confined to availability, with no disclosed compromise of confidentiality or integrity.
Affected Systems
All versions of ZJU-FAST-Lab EGO‑Planner‑v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. The vulnerability is present in the EGOReplanFSM component across the project’s codebase, regardless of the operating environment; no specific platform restrictions are mentioned.
Risk and Exploitability
The CVE entry does not provide a CVSS score or EPSS value, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote, using the network interface(s) that the EGOReplanFSM component exposes, though the official advisory does not state this explicitly. Because the flaw can cause a denial of service, the risk is moderate to high for systems that rely on continuous operation of the planner. Exploitation would require the attacker to send crafted input or induce a state that leads the FSM to crash; no elevated privileges are required as long as the affected component is publicly reachable.
OpenCVE Enrichment