PT-2024-35108 · Real Time Innovations · Rti Connext Professional

Published

2024-12-13

·

Updated

2025-10-02

·

CVE-2024-52058

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RTI Connext Professional versions 6.1.0 through 6.1.2.18 RTI Connext Professional versions 7.0.0 through 7.3.0.1
Description The issue is related to an OS Command Injection vulnerability, which allows for the injection of OS commands. This is due to the improper neutralization of special elements used in an OS command.
Recommendations For RTI Connext Professional versions 6.1.0 through 6.1.2.18, update to version 6.1.2.19 or later. For RTI Connext Professional versions 7.0.0 through 7.3.0.1, update to version 7.3.0.2 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-52058

Affected Products

Rti Connext Professional