Impact
An off‑by‑one error in RTI Connext Professional Core Libraries allows an out‑of‑bounds write that corrupts adjacent memory. The flaw can trigger crashes, disrupt data integrity, or enable an attacker to execute arbitrary code if a crafted payload is delivered. The weakness is identified by CWE‑193 and CWE‑787.
Affected Systems
The vulnerability affects RTI Connext Professional before 7.7.0.1 in the 7.4.0 release line and before 7.3.1.6 in the 7.0.0 line. Only the Core Libraries component is impacted.
Risk and Exploitability
With a CVSS score of 6.9 the flaw is considered moderate. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker sending a specially crafted message or packet over the Connext protocol that triggers the off‑by‑one error. The exploit requires the target to be exposed to the protocol and may be local or remote depending on network exposure. Because the flaw is an out‑of‑bounds write, even a single‑character miscalculation can corrupt memory, raising significant concerns for stability, data integrity, and potential privilege escalation.
OpenCVE Enrichment