Impact
The vulnerability in EGO‑Planner‑v2 allows an attacker to trigger the checkCollisionCallback, execFSMCallback, and planFromGlobalTraj functions defined in ego_replan_fsm.cpp. When these callbacks are called, the planner component can become unresponsive or terminate, impairing the availability of the system. The flaw does not grant code execution or privilege escalation.
Affected Systems
The affected software is the open‑source project EGO‑Planner‑v2 hosted on GitHub at https://github.com/ZJU-FAST-Lab up to and including commit 5c99a95880401e2599638d567abc0e240396cb42; the repository and its issue tracker can be found at the provided GitHub URLs CVSS score is 7.5, the EPSS score is less than 1%, and it is not listed in CISA’s KEV catalog, indicating a low likelihood of exploitation but a high impact if triggered; it likely requires local or is purely availability, the overall risk is moderate to high depending on the planner’s criticality to operational workflows.
Risk and Exploitability
The CVSS score of 7.5 signifies high severity, while the EPSS score of less than 1% indicates a very small probability of exploitation. It is not included in the CISA KEV catalog, further suggesting limited real‑world use. Based on the description, it is inferred that the vulnerability requires interaction with the planner’s internal callbacks, likely through a local or privileged context. If an attacker can invoke these callbacks, the planner will deny service, which can be significant for automated vehicle control workflows but does not compromise data confidentiality or integrity. The risk is thus high impact but low likelihood, making it a moderate overall threat. The key weakness is CWE‑400, indicating an unbounded resource allocation or denial of service vulnerability.
OpenCVE Enrichment