CVE-2021-38445: OCI OpenDDS Secure Improper Handling of Length Parameter Inconsistency
OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associated data, which may allow an attacker to remotely execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-38445.
What is the severity of CVE-2021-38445?
The severity of CVE-2021-38445 is critical with a severity value of 9.8.
What is the affected software for CVE-2021-38445?
The affected software for CVE-2021-38445 is OCI OpenDDS versions prior to 3.18.1.
What is the description of CVE-2021-38445?
CVE-2021-38445 is a vulnerability in OCI OpenDDS versions prior to 3.18.1 that allows an attacker to remotely execute arbitrary code due to improper handling of a length parameter.
Are there any references available for CVE-2021-38445?
Yes, there are references available for CVE-2021-38445. You can find them at the following links: [https://opendds.org/](https://opendds.org/) and [https://www.cisa.gov/uscert/ics/advisories/icsa-21-315-02](https://www.cisa.gov/uscert/ics/advisories/icsa-21-315-02).