CVE-2019-15136: High severity eprosima fast dds vulnerability
Published Aug 18, 2019
·Updated
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partition.
Affected Software
1 affected component
eProsima Fast-rtps<=1.9.0
Remediation
Patch Available
Event History
Aug 18, 2019
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-15136.
2
What is the severity of CVE-2019-15136?
The severity of CVE-2019-15136 is high with a CVSS score of 7.5.
3
Which software is affected by CVE-2019-15136?
Eprosima Fast-RTPS version 1.9.0 is affected by CVE-2019-15136.
4
What does CVE-2019-15136 allow?
CVE-2019-15136 allows policy bypass for a secure Data Distribution Service (DDS) partition.
5
Is there a fix available for CVE-2019-15136?
Yes, a fix is available for CVE-2019-15136. Please refer to the provided references for more information.