Generated remediation guidance and an executive summary. No account required.
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS crashes while parsing a malformed `PID_PROPERTY_LIST` in a DATA submessage during participant discovery. Attackers can remotely crash OpenDDS processes by sending a DATA submessage containing the malformed parameter to the known multicast port. This issue has been addressed in version 3.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Cite this page
CVE-2023-37915. CVEDatabase.com. Retrieved 3 May 2026. https://cvedatabase.com/cve/CVE-2023-37915
Use CWE-20, Objectcomputing vendor hub and Opendds product page to widen CVE-2023-37915 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-38447, CVE-2025-67111 and CVE-2023-52427 for nearby disclosures in the same product family.