CVE-2021-38425: eProsima Fast DDS Network Amplification
eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic, which may result in a denial-of-service condition and information exposure.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-38425?
CVE-2021-38425 is a vulnerability in eProsima Fast DDS versions prior to 2.4.0 that allows an attacker to flood a target device with unwanted traffic, resulting in a denial-of-service condition and information exposure.
How can CVE-2021-38425 be exploited?
CVE-2021-38425 can be exploited by sending a specially crafted packet to flood a target device with unwanted traffic.
What is the severity of CVE-2021-38425?
The severity of CVE-2021-38425 is dependent on the impact of the denial-of-service condition and the exposure of information.
Which versions of eProsima Fast DDS are affected by CVE-2021-38425?
Versions of eProsima Fast DDS prior to 2.4.0 are affected by CVE-2021-38425.
How can I fix CVE-2021-38425?
To fix CVE-2021-38425, update to version 2.4.0 or later of eProsima Fast DDS.
Where can I find more information about CVE-2021-38425?
More information about CVE-2021-38425 can be found at the [eProsima Fast DDS GitHub repository](https://github.com/eProsima/Fast-DDS) and the [CISA advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-21-315-02).