Impact
The vulnerability resides in the SignedDocument module of OpenDDS 3.33.x. A local attacker who can execute code within the same user context can trigger a denial of service by manipulating the verify function. This flaw leads to an unhandled error condition or resource exhaustion, ultimately causing the OpenDDS service to crash or become unresponsive. The weakness exemplifies a typical denial‑of‑service bug where the application fails to validate input or manage resources safely.
Affected Systems
The affected product is OpenDDS version 3.33.x. No specific vendor or sub‑product details are provided beyond the general OpenDDS name. Users running this specific release on any platform are potentially exposed, as the Verify function is part of the core DDS implementation used for security checks.
Risk and Exploitability
The CVSS score is 6.6, but the EPSS score is < 1% and it is not listed in CISA KEV, suggesting limited public exploitation. Nevertheless, the vulnerability can be exercised locally by anyone with write or execution permissions on the system, making it a serious internal risk. An attacker could abruptly terminate the DDS service, causing a local denial of service for all clients relying on that service. The risk is compounded in environments where OpenDDS handles critical real‑time or safety‑critical data streams.
OpenCVE Enrichment