CVE-2023-50257Improper Access Control in Fast-dds

Severity
8.1HIGHNVD
CNA9.6
EPSS
0.2%
top 61.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19

Description

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used to disconnect between nodes are not encrypted, a vulnerability has been discovered where a malicious attacker can forcibly disconnect a Subscriber and can deny a Subscriber attempting to connect. Afterwards, if the attacker sends the packet for disconnecting, wh

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5eprosima/fast-dds< 2.6.7+11
NVDeprosima/fast_dds2.10.02.10.3+3

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-50257: eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group2024-02-19
CVEList
Disconnect Vulnerability in RTPS Packets Used by SROS22024-02-19

📋Vendor Advisories

1
Debian
CVE-2023-50257: fastdds - eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distr...2023
CVE-2023-50257 — Improper Access Control in Fast-dds | cvebase