Impact
The vulnerability is governed by CWE‑682 and arises from an incorrect calculation within RTI Connext Professional’s core libraries. This flaw permits an attacker to abuse the software’s existing functionality, potentially causing unintended behaviour, system misconfiguration, or denial of service. The specific damage depends on how the calculation is used in the application but the flaw fundamentally undermines correct execution of business logic.
Affected Systems
The flaw affects RTI Connext Professional across multiple major releases. Vulnerable versions include those from 7.4.0 up to before 7.7.0.1; from 7.0.0 up to before 7.3.1.6; from 6.1.0 up to before 6.1.*; from 6.0.0 up to before 6.0.*; from 5.3.0 up to before 5.3.*; from 5.2.0 up to before 5.2.*; and from 4.1.x up to before 5.1.*.
Risk and Exploitability
With a base CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is not provided, and the flaw is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation yet. The likely attack vector is through application‑level interaction with Connext’s core libraries; it is inferred that an attacker could manipulate inputs or data passed to the affected components to trigger the incorrect calculation. As with many core‑library issues, the exploit would execute in the context of the vulnerable application, granting the attacker the same permissions as the running service.
OpenCVE Enrichment