Buffer Overflow Vulnerability in RTI Connext Professional Services
CVE-2024-25724

7.3HIGH

Key Information:

Vendor

RTI

Vendor
CVE Published:
21 May 2024

What is CVE-2024-25724?

A buffer overflow vulnerability exists in RTI Connext Professional versions 5.3.1 through 6.1.0 prior to 6.1.1, affecting key services including the Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service. This flaw enables potential attackers to execute arbitrary code under the service’s privileges, jeopardizing the integrity of the service. Attack vectors include sending malicious RTPS messages, invoking public APIs with compromised parameters, or manipulating local XML files. This could lead to unauthorized access to sensitive information or disrupt service functionality.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.