Description
Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6.
Published: 2026-09-22
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Buffer Overflow causing potential data corruption or local exploitation
Action: Update Product
AI Analysis

Impact

An off‑by‑one error in RTI Connext Professional Core Libraries allows an out‑of‑bounds write that corrupts adjacent memory. The flaw can trigger crashes, disrupt data integrity, or enable an attacker to execute arbitrary code if a crafted payload is delivered. The weakness is identified by CWE‑193 and CWE‑787.

Affected Systems

The vulnerability affects RTI Connext Professional before 7.7.0.1 in the 7.4.0 release line and before 7.3.1.6 in the 7.0.0 line. Only the Core Libraries component is impacted.

Risk and Exploitability

With a CVSS score of 6.9 the flaw is considered moderate. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker sending a specially crafted message or packet over the Connext protocol that triggers the off‑by‑one error. The exploit requires the target to be exposed to the protocol and may be local or remote depending on network exposure. Because the flaw is an out‑of‑bounds write, even a single‑character miscalculation can corrupt memory, raising significant concerns for stability, data integrity, and potential privilege escalation.

Generated by OpenCVE AI on September 22, 2026 at 20:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RTI Connext Professional to version 7.7.0.1 or later for the 7.4.0 line, or to 7.3.1.6 or later for the 7.0.0 line to eliminate the vulnerability.
  • If an upgrade is not immediately possible, restrict or disable Connext messaging interfaces on untrusted networks to reduce exposure to crafted payloads.
  • Apply additional input validation or sanitization to Connext messages as recommended by the vendor to reduce the likelihood that the off‑by‑one error can be triggered by malformed input.

Generated by OpenCVE AI on September 22, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6.
Title Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-193
CWE-787
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T18:47:21.507Z

Reserved: 2026-07-31T07:30:45.192Z

Link: CVE-2026-18460

cve-icon Vulnrichment

Updated: 2026-09-22T18:47:18.491Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:11.940

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-18460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:15:06Z

Weaknesses