CVE-2023-37915 HIGH

CVE-2023-37915: Malformed PID_PROPERTY_LIST parameter in DATA submessage remotely crashes OpenDDS

Vendor Opendds
Product OpenDDS
Weakness CWE-20 · Input validation
Published July 21, 2023
Last update October 10, 2024

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS crashes while parsing a malformed `PID_PROPERTY_LIST` in a DATA submessage during participant discovery. Attackers can remotely crash OpenDDS processes by sending a DATA submessage containing the malformed parameter to the known multicast port. This issue has been addressed in version 3.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Key dates

02Disclosure timeline

July 21, 2023 CVE published
October 10, 2024 Record updated