CVE-2021-38443

MEDIUM

Eclipse CycloneDDS <0.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.

Scores

CVSS v3 6.6
EPSS 0.0016
EPSS Percentile 36.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-228
Status published
Products (1)
eclipse/cyclonedds < 0.8.0
Published May 05, 2022
Tracked Since Feb 18, 2026