First published: Thu Apr 11 2024(Updated: )
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted max_samples parameter in DurabilityService QoS component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
eProsima Fast DDS | <=2.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30916 has a high severity as it allows local attackers to cause a denial of service and potentially access sensitive information.
To fix CVE-2024-30916, upgrade to eProsima FastDDS version 2.14.1 or later, which addresses the vulnerability.
Users of eProsima FastDDS versions up to and including 2.14.0 are affected by CVE-2024-30916.
CVE-2024-30916 is exploited through a crafted max_samples parameter in the DurabilityService QoS component causing a denial of service.
The specific sensitive information that may be exposed through CVE-2024-30916 includes internal state data that could be manipulated by a local attacker.