CVE-2025-14543: Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1., from 6.0.0 before 6.0., from 5.3.0 before 5.3., from 4.3x before 5.2..
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 7.7.0 - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 7.3.1.1 - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 6.1.* - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 6.0.* - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 5.3.* - Upgrade
Upgrade
RTI Connext Professional (Core Libraries)to a version that resolves this vulnerability.Fixed in 5.2.*
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14543?
CVE-2025-14543 is classified as a medium-severity vulnerability due to its potential for Serialized Data External Linking.
How do I fix CVE-2025-14543?
To fix CVE-2025-14543, upgrade to the latest version of Real-Time Innovations Connext Professional that is not affected by the vulnerability.
Which versions are affected by CVE-2025-14543?
Affected versions of Connext Professional include 5.2.x, 5.3.x, 6.0.x, 6.1.x, 7.0.0, 7.3.1.1, and up to 7.7.0.
What type of vulnerability is CVE-2025-14543?
CVE-2025-14543 is an Improper Restriction of XML External Entity Reference vulnerability.
What impact does CVE-2025-14543 have on my system?
CVE-2025-14543 may allow attackers to exploit serialized data through external entity references, potentially leading to sensitive data exposure.