HomeEprosimaCVE-2024-30259

CVE-2024-30259

HIGH
8.2CVSS
Published: 2024-05-14
Updated: 2025-01-27
AI Analysis

Description

FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflow occurs on the subscriber. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
low
Availability
high
Weaknesses
CWE-120CWE-122CWE-787

Metadata

Primary Vendor
EPROSIMA
Published
5/14/2024
Last Modified
1/27/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

eprosima : fast_ddseprosima : fast_ddseprosima : fast_ddseprosima : fast_dds

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-30259 | HIGH Severity | CVEDatabase.com | CVEDatabase.com