In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the RTI_RoutingService_new, rti::recording::Service, RTI_QueuingService_new, or RTI_CDS_Service_new public APIs; or a compromised local file system containing a malicious XML file.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Rti
Rti connext Dds Professional |
|
CPEs | cpe:2.3:a:rti:connext_dds_professional:5.3.1:*:*:*:*:*:*:* | |
Vendors & Products |
Rti
Rti connext Dds Professional |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-04T01:44:55.971Z
Reserved: 2024-02-11T00:00:00.000Z
Link: CVE-2024-25724

Updated: 2024-08-01T23:52:06.271Z

Status : Awaiting Analysis
Published: 2024-05-21T19:15:09.557
Modified: 2024-11-21T09:01:16.797
Link: CVE-2024-25724

No data.