CVE-2024-30917: Medium severity eprosima fast dds vulnerability
Published Apr 11, 2024
·Updated
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted historydepth parameter in DurabilityService QoS component.
Affected Software
2 affected components
eProsima FastDDS<2.14.0
eProsima Fast DDS<=2.14.0
Event History
Apr 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30917?
CVE-2024-30917 is classified as a denial of service vulnerability.
2
How do I fix CVE-2024-30917?
To mitigate CVE-2024-30917, you should upgrade to eProsima FastDDS version 2.14.1 or later.
3
What component is affected by CVE-2024-30917?
CVE-2024-30917 affects the DurabilityService QoS component in eProsima FastDDS.
4
Can CVE-2024-30917 be exploited remotely?
CVE-2024-30917 requires local access, so it cannot be exploited remotely.
5
What type of attack can CVE-2024-30917 facilitate?
CVE-2024-30917 can lead to a denial of service and exposure of sensitive information.