CVE-2024-52058: Potential arbitrary command execution in System Designer while parsing malicious HTTP/REST requests
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext Professional (System Designer) allows OS Command Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.0 before 6.1.2.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52058?
The severity of CVE-2024-52058 is rated as critical due to the potential for OS command injection.
How do I fix CVE-2024-52058?
To fix CVE-2024-52058, you should upgrade RTI Connext Professional to version 7.3.0.2 or 6.1.2.19 or later.
Which versions of RTI Connext Professional are affected by CVE-2024-52058?
CVE-2024-52058 affects RTI Connext Professional versions from 7.0.0 up to but not including 7.3.0.2 and from 6.1.0 up to but not including 6.1.2.19.
What type of vulnerability is CVE-2024-52058?
CVE-2024-52058 is classified as an OS Command Injection vulnerability.
Can CVE-2024-52058 be exploited remotely?
Yes, CVE-2024-52058 can potentially be exploited remotely if the application is accessible over a network.