Impact
The flaw is an out‑of‑bounds read in the core libraries of RTI Connext Professional; it permits reading data past buffer boundaries. This can expose contents residing in memory, such as secrets or other confidential data, and is classified as CWE‑125. No elevation of privilege or code execution is required, but sensitive information may be disclosed.
Affected Systems
The vulnerability affects RTI Connext Professional deployments across several major releases: from version 7.4.0 up to but not including 7.7.0; from 7.0.0 up to but not including 7.3.1.3; from 6.1.0 up to but not including 6.1.*; from 6.0.0 up to but not including 6.0.*; from 5.3.0 up to but not including 5.3.*; from 5.2.0 up to but not including 5.2.*; from 5.0.0 up to but not including 5.1.*.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1% signals a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires access to the same process memory or a privilege level that allows memory probing. The resulting information disclosure makes it a significant risk for environments that handle sensitive data within Connext services.
OpenCVE Enrichment