PT-2024-35108 · Real Time Innovations · Rti Connext Professional
Published
2024-12-13
·
Updated
2025-10-02
·
CVE-2024-52058
CVSS v4.0
8.6
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RTI Connext Professional versions 6.1.0 through 6.1.2.18
RTI Connext Professional versions 7.0.0 through 7.3.0.1
Description
The issue is related to an OS Command Injection vulnerability, which allows for the injection of OS commands. This is due to the improper neutralization of special elements used in an OS command.
Recommendations
For RTI Connext Professional versions 6.1.0 through 6.1.2.18, update to version 6.1.2.19 or later.
For RTI Connext Professional versions 7.0.0 through 7.3.0.1, update to version 7.3.0.2 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rti Connext Professional