github.com
https://github.com/OpenDDS/OpenDDS/releases/tag/DDS-3.25 CVE-2023-37915
HIGH
Malformed PID_PROPERTY_LIST parameter in DATA submessage remotely crashes OpenDDS
Record summary
CVE-2023-37915 has a selected CVSS score of 7.5 (high).
Description
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS crashes while parsing a malformed `PID_PROPERTY_LIST` in a DATA submessage during participant discovery. Attackers can remotely crash OpenDDS processes by sending a DATA submessage containing the malformed parameter to the known multicast port. This issue has been addressed in version 3.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 10, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
OpenDDSBrowse OpenDDS / OpenDDS | CVE List | < 3.25 | affected |
Default status: unknown | CVE List | Before 3.25 | affected |
References
2github.comConfirmation
https://github.com/OpenDDS/OpenDDS/security/advisories/GHSA-v5pp-7prc-5xq9