CVE-2021-38427: RTI Connext DDS Professional and Connext DDS Secure Stack-based Buffer Overflow
Published May 5, 2022
·Updated
RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code.
Affected Software
11 affected componentsFixes available
RTI Connext DDS Professional>=4.2.0<=6.1.0
RTI Connext DDS Secure>=4.2.0<=6.1.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Eclipse CycloneDDS<0.8.0
0.8.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing eProsima Fast DDS (#2269)<2.4.0
2.4.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing GurumNetworks GurumDDS
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Object Computing, Inc. (OCI) OpenDDS<3.18.1
3.18.1
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Real-Time Innovations (RTI) Connext DDS Professional and Connext DDS Secure: Versions 4.2x to 6.1.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing RTI Connext DDS Micro>=3.0.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing TwinOaks Computing CoreDX DDS<5.9.1
5.9.1
RTI Connext Professional>=4.2.0<=6.1.0
RTI Connext Secure>=4.2.0<=6.1.0
Remediation
Information
RTI recommends users apply the available patches for these issues. A patch is available on the RTI customer portal or by contacting RTI Support. Also, contact RTI Support for mitigations, including how to use RTI DDS Secure to mitigate against the network amplification issue.
Event History
May 5, 2022
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-38427.
2
What is the severity of CVE-2021-38427?
The severity of CVE-2021-38427 is high with a CVSS score of 7.8.
3
Which versions of RTI Connext DDS Professional are affected?
Versions 4.2.x to 6.1.0 of RTI Connext DDS Professional are affected.
4
Which versions of RTI Connext DDS Secure are affected?
Versions 4.2.x to 6.1.0 of RTI Connext DDS Secure are affected.
5
How can a local attacker exploit this vulnerability?
A local attacker can exploit this vulnerability to execute arbitrary code.