Description
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.3x before 5.1.*.
Published: 2026-04-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via XML External Entity (XEE) processing
Action: Apply patch
AI Analysis

Impact

An attacker can craft XML that includes external entity references. When parsed by RTI Connext Professional Core Libraries, the parser attempts to resolve these references, resulting in serialized data external linking and potential exposure of local files or network resources. The flaw is a classic XML External Entity problem described by CWE‑611, and does not provide a direct code‑execution avenue; its primary impact is confidential data leakage.

Affected Systems

RTI Connext Professional Core Libraries versions from 4.3x before 5.1.*, from 5.2.0 before 5.2.*, from 5.3.0 before 5.3.*, from 6.0.0 before 6.0.*, from 6.1.0 before 6.1.*, from 7.0.0 before 7.3.1.1, and from 7.4.0 before 7.7.0.

Risk and Exploitability

The CVSS score of 6.9 classifies the vulnerability as medium severity while the EPSS score of less than 1% indicates a very low likelihood of exploitation; the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is via any application or service that parses XML input using the affected Connext libraries. Exploitation would involve sending a malicious XML document that triggers the parser to fetch external resources, enabling an attacker to read data they should not see, although no public exploit has been reported.

Generated by OpenCVE AI on September 22, 2026 at 20:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest RTI Connext Professional release that addresses the XEE flaw (for example, 7.7.0 or newer, or the corresponding patched release for earlier branches).
  • Configure the Connext XML parser to disallow external entity resolution, ensuring that any DOCTYPE or external entity declarations are ignored or blocked.
  • Validate and sanitize all XML input prior to parsing, rejecting untrusted or externally sourced XML documents that may contain malicious entity references.

Generated by OpenCVE AI on September 22, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*. Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.3x before 5.1.*.

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Description Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*. Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.
Title Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking. Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.

Mon, 04 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Thu, 30 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
Description Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.
Title Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-611
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T17:49:59.936Z

Reserved: 2025-12-11T15:00:13.943Z

Link: CVE-2025-14543

cve-icon Vulnrichment

Updated: 2026-04-30T15:42:18.952Z

cve-icon NVD

Status : Modified

Published: 2026-04-30T16:16:40.420

Modified: 2026-09-22T18:17:09.093

Link: CVE-2025-14543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:00:16Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference