CVE-2021-38441: Eclipse CycloneDDS Write-what-where Condition
Published May 5, 2022
·Updated
Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.
Affected Software
8 affected componentsFixes available
Eclipse CycloneDDS<0.8.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Eclipse CycloneDDS<0.8.0
0.8.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing eProsima Fast DDS (#2269)<2.4.0
2.4.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing GurumNetworks GurumDDS
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Object Computing, Inc. (OCI) OpenDDS<3.18.1
3.18.1
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Real-Time Innovations (RTI) Connext DDS Professional and Connext DDS Secure: Versions 4.2x to 6.1.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing RTI Connext DDS Micro>=3.0.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing TwinOaks Computing CoreDX DDS<5.9.1
5.9.1
Remediation
Information
Eclipse recommends users apply the latest CycloneDDS patches.
https://projects.eclipse.org/projects/iot.cyclonedds
Event History
May 5, 2022
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for Eclipse CycloneDDS?
The vulnerability ID for Eclipse CycloneDDS is CVE-2021-38441.
2
What is the severity of CVE-2021-38441?
The severity of CVE-2021-38441 is critical with a severity value of 9.8.
3
Which versions of Eclipse CycloneDDS are affected by CVE-2021-38441?
Versions of Eclipse CycloneDDS prior to 0.8.0 are affected by CVE-2021-38441.
4
What is the impact of CVE-2021-38441?
CVE-2021-38441 allows an attacker to write arbitrary values in the XML parser, which can lead to unauthorized modification of data.
5
How can I mitigate the vulnerability in Eclipse CycloneDDS?
To mitigate the vulnerability in Eclipse CycloneDDS, it is recommended to update to version 0.8.0 or later.