cbcvebase.

Eprosima Fast Dds vulnerabilities

27 known vulnerabilities affecting eprosima/fast_dds.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH21MEDIUM2

Vulnerabilities

Page 2 of 2
CVE-2023-39948P3HIGHCVSS 7.5≥ 2.6.0, < 2.6.5v2.10.02023-08-11
CVE-2023-39948 [HIGH] CWE-248 CVE-2023-39948: eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Ma eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any Fast DDS process. Versions 2.10.0 and 2.6.5 contain a patch for this issue.
nvd
CVE-2025-63829P3HIGHCVSS 7.5≤ 3.3.02025-11-18
CVE-2025-63829 [HIGH] CWE-190 CVE-2025-63829: eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in t eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction() function.
nvd
CVE-2025-65865P3HIGHCVSS 7.5v3.3.02025-12-23
CVE-2025-65865 [HIGH] CWE-190 CVE-2025-65865: An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) vi An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
nvd
CVE-2025-64098P4MEDIUMCVSS 5.9fixed in 2.6.11≥ 3.0.0, < 3.3.1+1 more2026-02-03
CVE-2025-64098 [MEDIUM] CWE-125 CVE-2025-64098: Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition, resulting in remote termination of Fast-
nvd
CVE-2025-24807P4HIGHCVSS 7.1fixed in 2.6.10≥ 2.10.0, < 2.10.7+3 more2025-02-11
CVE-2025-24807 [HIGH] CWE-345 CVE-2025-24807: eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0, per design, PermissionsCA is not full chain validated, nor is the expiration date validated. Access control plugin validates only the S/MIME signature which c
nvd
CVE-2024-30916P4HIGHCVSS 7.1≤ 2.14.02024-04-11
CVE-2024-30916 [HIGH] CWE-20 CVE-2024-30916: An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted max_samples parameter in DurabilityService QoS component.
nvd
CVE-2024-30917P4MEDIUMCVSS 5.5≤ 2.14.02024-04-11
CVE-2024-30917 [MEDIUM] CWE-229 CVE-2024-30917: An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted history_depth parameter in DurabilityService QoS component.
nvd
Eprosima Fast Dds vulnerabilities | cvebase