CVE-2025-67109: Critical severity Eclipse Cyclone DDS vulnerability
Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67109?
CVE-2025-67109 is considered high severity due to its potential to allow attackers to bypass certificate checks and execute commands with system privileges.
How do I fix CVE-2025-67109?
To fix CVE-2025-67109, upgrade Eclipse Cyclone DDS to version 0.10.5 or later where the vulnerability is addressed.
Which versions of Eclipse Cyclone DDS are affected by CVE-2025-67109?
Eclipse Cyclone DDS versions prior to 0.10.5 are affected by CVE-2025-67109.
What type of attack does CVE-2025-67109 allow?
CVE-2025-67109 allows attackers to execute arbitrary commands with system privileges due to improper certificate time verification.
Is there a workaround for CVE-2025-67109?
There is no documented workaround for CVE-2025-67109; upgrading to the latest version is recommended.