CVE-2021-43547: TwinOaks Computing CoreDX DDS Secure Network Amplification
Published May 5, 2022
·Updated
TwinOaks Computing CoreDX DDS versions prior to 5.9.1 are susceptible to exploitation when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.
Affected Software
8 affected componentsFixes available
Twinoakscomputing Coredx Dds<5.9.1
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Eclipse CycloneDDS<0.8.0
0.8.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing eProsima Fast DDS (#2269)<2.4.0
2.4.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing GurumNetworks GurumDDS
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Object Computing, Inc. (OCI) OpenDDS<3.18.1
3.18.1
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing Real-Time Innovations (RTI) Connext DDS Professional and Connext DDS Secure: Versions 4.2x to 6.1.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing RTI Connext DDS Micro>=3.0.0
Eclipse, eProsima, GurumNetworks, Object Computing, Inc. (OCI), Real-Time Innovations (RTI), TwinOaks Computing TwinOaks Computing CoreDX DDS<5.9.1
5.9.1
Remediation
Information
Twin Oaks Computing recommends users apply CoreDX DDS Version 5.9.1 or later, which can be downloaded on the Twin Oaks website http://www.twinoakscomputing.com/coredx/download (login required).
Event History
May 5, 2022
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-43547?
CVE-2021-43547 is classified as a denial-of-service vulnerability, which can lead to potential disruptions in service.
2
How do I fix CVE-2021-43547?
To mitigate CVE-2021-43547, upgrade to TwinOaks Computing CoreDX DDS version 5.9.1 or later.
3
Which versions are affected by CVE-2021-43547?
CVE-2021-43547 affects TwinOaks Computing CoreDX DDS versions prior to 5.9.1.
4
What types of devices are impacted by CVE-2021-43547?
CVE-2021-43547 can affect any devices running vulnerable versions of TwinOaks Computing CoreDX DDS.
5
Can CVE-2021-43547 lead to information exposure?
Yes, exploiting CVE-2021-43547 can lead to possible information exposure due to unwanted traffic flooding.