Impact
In PX4 Autopilot versions up to and including 1.17.0 a null pointer dereference occurs in the param_set_default_file() and param_set_backup_file() functions when the ‘param select’ or ‘param select-backup’ commands are invoked without a path argument. The vulnerability does not leak data but causes the autopilot process to crash, resulting in a loss of flight control or system availability. This is a local denial‑of‑service flaw that can be triggered by any user with shell access to the PX4 system.
Affected Systems
All deployments of PX4 Autopilot version 1.17.0 or earlier are affected. The vulnerability is identified in the PX4:PX4-Autopilot product line under the version identifier 1.17.0 and earlier iterations.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high impact. The exploit requires local access to the PX4 shell; no network attack vector is disclosed. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying current exploitation activity has not been observed. Attackers who can run the param commands can simply crash the autopilot process by supplying no argument, which can be used for opportunistic disruption.
OpenCVE Enrichment