cbcvebase.
CVE-2021-38425
published 2022-05-05

CVE-2021-38425: eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device…

PriorityP355critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
5.24%
91.6th percentile
eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic, which may result in a denial-of-service condition and information exposure.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianfastdds< fastdds 2.6.1+ds-1 (bookworm)fastdds 2.6.1+ds-1 (bookworm)
eprosimafast_dds< 2.4.02.4.0
eprosimafast_dds>= unspecified < 2.4.0 (#2269)2.4.0 (#2269)

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.