First published: Fri Dec 13 2024(Updated: )
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext Professional (System Designer) allows OS Command Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.0 before 6.1.2.19.
Credit: 3f572a00-62e2-4423-959a-7ea25eff1638
Affected Software | Affected Version | How to fix |
---|---|---|
RTI Connext DDS Professional | >=7.0.0<7.3.0.2 | |
RTI Connext DDS Professional | >=6.1.0<6.1.2.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-52058 is rated as critical due to the potential for OS command injection.
To fix CVE-2024-52058, you should upgrade RTI Connext Professional to version 7.3.0.2 or 6.1.2.19 or later.
CVE-2024-52058 affects RTI Connext Professional versions from 7.0.0 up to but not including 7.3.0.2 and from 6.1.0 up to but not including 6.1.2.19.
CVE-2024-52058 is classified as an OS Command Injection vulnerability.
Yes, CVE-2024-52058 can potentially be exploited remotely if the application is accessible over a network.