Impact
An out-of-bounds read, incorrect function argument count, and type confusion in the core libraries allow an attacker to overread interior buffers. The CVE groups these weaknesses under CWE‑125, CWE‑685, and CWE‑843. A successful exploit could expose memory contents beyond the intended buffer, leading to information disclosure or service destabilization from data corruption.
Affected Systems
RTI Connext Professional Core Libraries, specifically versions 7.4.0 prior to 7.7.0.1, 7.3.0 prior to 7.3.1.6, and 6.1.2.21 prior to 6.1.*. Systems running any of these releases are vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates a serious but not critical impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based, requiring the attacker to communicate with the Connext services; local exploitation may also be feasible for processes running with elevated privileges. Because the flaw reads uncontrolled memory, an attacker could gain sensitive data or cause a crash, depending on how the buffer is treated. No immediate exploits are publicly known, but the lack of a KEV listing does not rule out later exploitation.
OpenCVE Enrichment