PT-2024-21114 · Real Time Innovations · Rti Connext Professional
Philip Pettersson
·
Published
2024-05-21
·
Updated
2025-10-21
·
CVE-2024-25724
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RTI Connext Professional versions 5.3.1 through 6.1.0
Description
A buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the
RTI RoutingService new, rti::recording::Service, RTI QueuingService new, or RTI CDS Service new public APIs; or a compromised local file system containing a malicious XML file.Recommendations
For RTI Connext Professional versions 5.3.1 through 6.1.0, update to version 6.1.1 to protect against potential code execution and information leaks. As a temporary workaround, consider restricting access to the vulnerable services until the update is applied. Avoid using malicious parameters in the affected public APIs until the issue is resolved.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rti Connext Professional