CVE-2023-39949
moderate-risk
Published 2023-08-11
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
Do I need to act?
-
0.11% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (4)
References (8)
Third Party Advisory
https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageRe...
Third Party Advisory
https://github.com/eProsima/Fast-DDS/issues/3236
Third Party Advisory
https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cg
Third Party Advisory
https://www.debian.org/security/2023/dsa-5481
Third Party Advisory
https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageRe...
Third Party Advisory
https://github.com/eProsima/Fast-DDS/issues/3236
Third Party Advisory
https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cg
Third Party Advisory
https://www.debian.org/security/2023/dsa-5481
36
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
0/34 · Minimal
Exposure
10/34 · Low