CVE-2024-30916: Input Validation
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted maxsamples parameter in DurabilityService QoS component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30916?
CVE-2024-30916 has a high severity as it allows local attackers to cause a denial of service and potentially access sensitive information.
How do I fix CVE-2024-30916?
To fix CVE-2024-30916, upgrade to eProsima FastDDS version 2.14.1 or later, which addresses the vulnerability.
Who is affected by CVE-2024-30916?
Users of eProsima FastDDS versions up to and including 2.14.0 are affected by CVE-2024-30916.
What kind of attack is exploited in CVE-2024-30916?
CVE-2024-30916 is exploited through a crafted max_samples parameter in the DurabilityService QoS component causing a denial of service.
What sensitive information can be obtained via CVE-2024-30916?
The specific sensitive information that may be exposed through CVE-2024-30916 includes internal state data that could be manipulated by a local attacker.