Impact
The heap-based buffer overflow in the core libraries of RTI Connext Professional is triggered when the system processes custom variables and tags, allowing an attacker to overwrite memory. This flaw can corrupt data and, given its heap nature, may enable arbitrary code execution, potentially compromising confidentiality, integrity, and availability of the affected deployment. The flaw exists in a range of releases, from 5.0.0 up to just before 7.7.0, as identified in the vendor’s advisory.
Affected Systems
RTI Connext Professional, versions 7.4.0 through just before 7.7.0, 7.0.0 through 7.3.1.3, 6.1.0 through any 6.1.x, 6.0.0 through any 6.0.x, 5.3.0 through any 5.3.x, and 5.0.0 through any 5.2.x.
Risk and Exploitability
The CVSS score for this issue is 8.2, indicating high severity. The EPSS score is below 1 %, meaning the likelihood of exploitation observed in the wild is low but non‑zero. The vulnerability is not listed in CISA’s KEV catalog. The flaw is likely exploitable by sending crafted messages containing malformed variables or tags over the network to a Connext Participant, making the attack vector remote.
OpenCVE Enrichment