Impact
OpenDDS is a C++ implementation of the OMG Data Distribution Service that allows participants to exchange messages over a network. A malformed RTPS UDP submessage containing a crafted length or sequence number can cause the library to read past the end of a message buffer. The parser then dereferences this invalid pointer, triggering a segmentation fault in the receive thread. The fault terminates the DDS process and removes all entities for that participant. Because the attack requires only a crafted packet sent over the network, no authentication or prior state is needed, giving any remote attacker the ability to bring a reachable OpenDDS instance down. The flaw is a CWE‑125 out‑of‑bounds read.
Affected Systems
The vulnerability affects all OpenDDS installations with a version earlier than 3.34.0, regardless of platform. The issue is fixed in the 3.34.0 release, so any deployment running 3.34.0 or later is no longer susceptible.
Risk and Exploitability
The CVSS v3.1 score of 8.7 places the flaw in the high severity range, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. It is not currently listed in the CISA KEV catalog. An attacker can exploit the vulnerability remotely over the standard RTPS UDP ports with a single crafted packet, without any authentication or additional interactions. Successful exploitation causes a denial of service by crashing the participant process and tearing down the DDS entities it hosts.
OpenCVE Enrichment