Impact
Out‑of‑bounds read in RTI Connext Professional Core Libraries permits an attacker to consume portions of memory that lie beyond intended buffer limits. This flaw could expose sensitive internal data, such as authentication tokens or user information, depending on the context in which the vulnerable component is executed. The weakness is classified as CWE‑125, which generally allows an attacker to gain unintended visibility into memory contents, compromising confidentiality without immediate code execution.
Affected Systems
The vulnerability applies to versions of RTI Connext Professional that precede the following release points: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, and from 5.0.0 before 5.1.*. Systems running any of these binaries are at risk unless the software is upgraded beyond the cited versions.
Risk and Exploitability
The CVSS score of 6.8 places this issue in the medium severity range, indicating that while exploitation does not lead to immediate control, the potential for data leakage is significant. No EPSS data is available, so the likelihood of exploitation in the wild cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been identified as a high‑impact target by national security monitoring. Based on the description, it is inferred that the attack vector is local or requires some degree of code execution within the affected application; the mechanism for triggering the overread is not explicitly detailed.
OpenCVE Enrichment