Impact
The vulnerability is an out‑of‑bounds read in the core libraries of RTI Connext Professional, caused by a function call with incorrect arguments and a type‑confusion bug that permits reading beyond buffer limits. This bug can lead to information disclosure or memory corruption when the application processes maliciously crafted inputs. The weakness aligns with CWE‑125 (Out‑of‑Bounds Read), CWE‑685 (Argument Count Mismatch), and CWE‑843 (Type Confusion).
Affected Systems
RTI Connext Professional from version 7.4.0 up to but not including 7.7.0.1, and from version 7.3.0 up to but not including 7.3.1.6 are affected. All other versions are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity vulnerability. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the known exploitation likelihood is uncertain. The potential attack vector is inferred to be remote, as the bug involves an out‑of‑bounds read triggered by malformed network messages sent to the RTI Connext services. Successful exploitation would expose sensitive data or corrupt memory within the affected process, thereby compromising confidentiality or integrity of the application. The lack of an official exploit in the KEV repository suggests that active exploitation may be limited, but the medium severity and the possibility of remote triggering warrants careful monitoring and timely patching.
OpenCVE Enrichment