PT-2025-11036 · Eclipse Foundation+3 · Eclipse Cyclonedds+2
Robert Femmer
+1
·
Published
2025-03-12
·
Updated
2025-03-14
·
CVE-2024-10838
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
The product name cannot be determined.
Description:
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory, potentially leading to the inclusion of secret data or pointers that reveal the layout of the address space into a deserialized data structure. This could result in thread crashes or denial of service conditions. Unauthenticated users could exploit this issue to access sensitive data or crash threads.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Cyclonedds
Cyclone Data Distribution Service
Cyclonedds