Impact
A buffer over‑read flaw exists in the Core Libraries of RTI Connext Professional, allowing an attacker to read memory beyond the bounds of allocated buffers. The CVE description indicates that the over‑read can occur under certain conditions, but the precise impact on data confidentiality, integrity, or availability is not fully defined in the advisory.
Affected Systems
RTI Connext Professional Core Libraries are affected across multiple major releases. Vulnerable versions include those from 7.4.0 up to but not including 7.7.0, from 7.0.0 up to but not including 7.3.1.1, from 6.1.0 up to but not including 6.1.2.34, from 6.0.0 up to but not including 6.0.*, from 5.3.0 up to but not including 5.3.*, from 5.2.0 up to but not including 5.2.*, and from 4.3.x up to but not including 5.1.*.
Risk and Exploitability
CVSS score of 4.8 indicates low severity while EPSS score below 1% suggests a very low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. The CVE description does not mention a remote attack surface, and it is inferred that exploitation would likely require local execution or code running within a process that loads the vulnerable library. Therefore, risk to environments depends on whether untrusted inputs are handled by the Core Libraries, but the potential impact is limited.
OpenCVE Enrichment