CVE-2023-37915: Malformed PID_PROPERTY_LIST parameter in DATA submessage remotely crashes OpenDDS
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS crashes while parsing a malformed PIDPROPERTYLIST in a DATA submessage during participant discovery. Attackers can remotely crash OpenDDS processes by sending a DATA submessage containing the malformed parameter to the known multicast port. This issue has been addressed in version 3.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenDDSto a version that resolves this vulnerability.Fixed in 3.25
Event History
Frequently Asked Questions
What is CVE-2023-37915?
CVE-2023-37915 is a vulnerability in OpenDDS, an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS).
What is the severity of CVE-2023-37915?
CVE-2023-37915 is considered to be a high severity vulnerability with a severity score of 7.5.
How does CVE-2023-37915 affect OpenDDS?
CVE-2023-37915 causes OpenDDS to crash while parsing a malformed `PID_PROPERTY_LIST` in a DATA submessage during participant discovery.
What is the affected software version of CVE-2023-37915?
OpenDDS version 3.23.1 is affected by CVE-2023-37915.
How can attackers exploit CVE-2023-37915?
Attackers can remotely crash OpenDDS processes by sending a DATA submessage with a malformed `PID_PROPERTY_LIST`.