eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0, per design, PermissionsCA is not full chain validated, nor is the expiration date validated. Access control plugin validates only the S/MIME signature which causes an expired PermissionsCA to be taken as valid. Even though this issue is responsible for allowing `governance/permissions` from an expired PermissionsCA and having the system crash when PermissionsCA is not self-signed and contains the full-chain, the impact is low. Versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0 contain a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Feb 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Eprosima
Eprosima fast Dds |
|
CPEs | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* | |
Vendors & Products |
Eprosima
Eprosima fast Dds |
|
Metrics |
cvssV3_1
|
Tue, 11 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Feb 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0, per design, PermissionsCA is not full chain validated, nor is the expiration date validated. Access control plugin validates only the S/MIME signature which causes an expired PermissionsCA to be taken as valid. Even though this issue is responsible for allowing `governance/permissions` from an expired PermissionsCA and having the system crash when PermissionsCA is not self-signed and contains the full-chain, the impact is low. Versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0 contain a fix for the issue. | |
Title | Fast DDS does not verify Permissions CA | |
Weaknesses | CWE-345 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-11T16:12:41.714Z
Reserved: 2025-01-23T17:11:35.840Z
Link: CVE-2025-24807

Updated: 2025-02-11T16:12:36.763Z

Status : Analyzed
Published: 2025-02-11T16:15:51.190
Modified: 2025-02-21T15:26:57.507
Link: CVE-2025-24807

No data.