PT-2024-35117 · Real Time Innovations · Rti Connext Professional

Published

2024-12-13

·

Updated

2025-10-02

·

CVE-2024-52066

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RTI Connext Professional versions 6.0.0 through 6.0.1.40 RTI Connext Professional versions 6.1.0 through 6.1.2.21 RTI Connext Professional versions 7.0.0 through 7.3.0.5 RTI Connext Professional versions 7.4.0 through 7.4.x before 7.5.0
Description The issue is a buffer copy without checking the size of the input, also known as a 'classic buffer overflow', in RTI Connext Professional's Routing Service. This problem allows for the overflow of variables and tags.
Recommendations For versions 6.0.0 through 6.0.1.40, update to version 6.0.1.40 or later. For versions 6.1.0 through 6.1.2.21, update to version 6.1.2.21 or later. For versions 7.0.0 through 7.3.0.5, update to version 7.3.0.5 or later. For versions 7.4.0 through 7.4.x before 7.5.0, update to version 7.5.0 or later.

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-52066

Affected Products

Rti Connext Professional