Impact
RTI Connext Professional, encompassing services such as Cloud Discovery, Recording, Routing, Queueing, and Observability Collector, contains an Improper Restriction of XML External Entity (XXE) reference vulnerability. The description indicates that the flaw permits processing of serialized data with external XML entities, enabling external linking and blowup of data serialization. An attacker who supplies crafted XML can trigger the vulnerability, potentially reading local files, accessing network resources, or causing denial‑of‑service by exhausting resources. The CVE does not explicitly mention remote code execution; that implication is inferred only if additional exploitation paths are present.
Affected Systems
The vulnerability affects the RTI Connext Professional product suite, specifically its Routing Service, Observability Collector, Recording Service, Queueing Service, and Cloud Discovery Service. Affected versions include 7.4.0 before 7.7.0, 7.0.0 before 7.3.1.1, 6.1.0 before 6.1.2.34, 6.0.0 before 6.0.*, and 5.3.0 before 5.3.*.
Risk and Exploitability
The CVSS v3.1 score is 7.0, indicating a high impact severity. EPSS score is < 1%, suggesting a low exploitation probability, and the issue is not listed in the CISA KEV catalog, indicating limited exploitation evidence. The likely attack vector is remote through untrusted XML input, inferred from the description and the nature of XXE weaknesses. Given the high CVSS, the risk to affected systems remains significant until mitigated.
OpenCVE Enrichment