Impact
This vulnerability is a stack-based buffer overflow in the core libraries of RTI Connext Professional. It allows an attacker to corrupt the execution stack when malformed data is processed. Such corruption can lead to the execution of arbitrary code or the denial of service by crashing the application.
Affected Systems
RTI:Connext Professional versions affected include 7.4.0 through 7.7.0.0, 7.0.0 through 7.3.1.5, 6.1.0 through 6.1.*, 6.0.0 through 6.0.*, 5.3.0 through 5.3.*, 5.2.0 through 5.2.*, and 4.3.x through 5.1.*. All earlier releases in these version ranges are vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity. The EPSS score is not provided, so the exact exploitation probability is uncertain. The vulnerability is not listed in the CISA KEV catalog, but the high severity and common nature of buffer overflows suggest that attacks are plausible, especially if the affected component is exposed to external networks.
OpenCVE Enrichment