CVE-2025-67108
published 2025-12-23CVE-2025-67108: eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
PriorityP354critical10CVSS 3.1
AVNACLPRNUINSCCHIHAN
EPSS
0.26%
17.5th percentile
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fastdds | — | — |
| eprosima | fast_dds | — | — |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-67108: fastdds - eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket ...
vendor_debian·2025·CVSS 10.0
CVE-2025-67108 [CRITICAL] CVE-2025-67108: fastdds - eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket ...
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
Scope: local
bookworm: undetermined
bullseye: undetermined
forky: undetermined
sid: undetermined
trixie: undetermined
GHSA
GHSA-839g-33gc-x4w2: eProsima Fast-DDS v3
ghsa_unreviewed·2025-12-23
CVE-2025-67108 [CRITICAL] CWE-298 GHSA-839g-33gc-x4w2: eProsima Fast-DDS v3
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
OSV
CVE-2025-67108: eProsima Fast-DDS v3
osv·2025-12-23·CVSS 10.0
CVE-2025-67108 [CRITICAL] CVE-2025-67108: eProsima Fast-DDS v3
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
No detection rules found.
No public exploits indexed.
2025-12-23
Published