CVE-2023-50257 — Improper Access Control in Fast-dds
Severity
8.1HIGHNVD
CNA9.6
EPSS
0.2%
top 61.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19
Description
eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used to disconnect between nodes are not encrypted, a vulnerability has been discovered where a malicious attacker can forcibly disconnect a Subscriber and can deny a Subscriber attempting to connect. Afterwards, if the attacker sends the packet for disconnecting, wh…
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2
Affected Packages2 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2023-50257: fastdds - eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distr...↗2023