First published: Thu May 05 2022(Updated: )
eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic, which may result in a denial-of-service condition and information exposure.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
eprosima Fast DDS | <2.4.0 | |
ubuntu/fastdds | <2.10.1+ | 2.10.1+ |
ubuntu/fastdds | <2.5.0+ | 2.5.0+ |
debian/fastdds | 2.1.0+ds-9+deb11u1 2.9.1+ds-1+deb12u2 2.11.2+ds-6 | |
<0.8.0 | 0.8.0 | |
<2.4.0 | 2.4.0 | |
<3.18.1 | 3.18.1 | |
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Real-Time Innovations (RTI) Connext DDS Professional and Connext DDS Secure: Versions 4.2x to 6.1.0 | ||
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing RTI Connext DDS Micro | >=3.0.0 | |
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing TwinOaks Computing CoreDX DDS | <5.9.1 | 5.9.1 |
eProsima recommends users apply the latest Fast DDS patches. https://github.com/eProsima/Fast-DDS
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38425 is a vulnerability in eProsima Fast DDS versions prior to 2.4.0 that allows an attacker to flood a target device with unwanted traffic, resulting in a denial-of-service condition and information exposure.
CVE-2021-38425 can be exploited by sending a specially crafted packet to flood a target device with unwanted traffic.
The severity of CVE-2021-38425 is dependent on the impact of the denial-of-service condition and the exposure of information.
Versions of eProsima Fast DDS prior to 2.4.0 are affected by CVE-2021-38425.
To fix CVE-2021-38425, update to version 2.4.0 or later of eProsima Fast DDS.
More information about CVE-2021-38425 can be found at the [eProsima Fast DDS GitHub repository](https://github.com/eProsima/Fast-DDS) and the [CISA advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-21-315-02).