CVE-2021-38487: Potential Network Amplification and Information Exposure in RTI Connext Professional and Connext Micro
RTI Connext DDS Professional, Connext DDS Secure versions 4.2x to 6.1.0, and Connext DDS Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.
Other sources
RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38487?
The severity of CVE-2021-38487 is critical, with a severity score of 9.1.
Which versions of RTI Connext DDS Professional and Connext DDS Secure are affected by CVE-2021-38487?
RTI Connext DDS Professional versions 4.2x to 6.1.0 and Connext DDS Secure versions 4.2x to 6.1.0 are affected by CVE-2021-38487.
Which versions of RTI Connext DDS Micro are affected by CVE-2021-38487?
RTI Connext DDS Micro versions 2.4 and later are affected by CVE-2021-38487.
What is the impact of CVE-2021-38487?
CVE-2021-38487 can result in a denial-of-service condition and information exposure.
Where can I find more information about CVE-2021-38487?
More information about CVE-2021-38487 can be found at the following references: [Link 1](https://support.rti.com/s/login/?ec=302&startURL=%2Fs%2F), [Link 2](https://www.cisa.gov/uscert/ics/advisories/icsa-21-315-02).