Improper Time Certificate Verification in Eclipse Cyclone DDS
CVE-2025-67109
10CRITICAL
What is CVE-2025-67109?
Eclipse Cyclone DDS versions before 0.10.5 exhibit a security flaw related to the improper validation of time certificates. This issue enables attackers to bypass essential certificate checks, opening a pathway for unauthorized command execution with system privileges. The vulnerability could lead to severe consequences if exploited, making remediation critical in affected installations.
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
