CVE-2025-24807

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 21, 2025
CWE ID 345

Summary

CVE-2025-24807 affects eprosima Fast DDS, a C++ implementation of the Data Distribution Service (DDS) standard by the Object Management Group. Prior to specific versions, this vulnerability arises due to insufficient validation of Permissions Certificate Authorities (CA). The access control plugin only verifies the S/MIME signature, allowing expired PermissionsCAs to be accepted. Despite the potential for system crashes when the PermissionsCA is not self-signed, the impact is low. Versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0 have been released with a fix for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • eProsima Fast DDS

Affected Vendors

  • eProsima