CVE-2023-39949
Improper validation of sequence numbers leading to remotely reachable assertion failure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
eprosima Fast DDS es una implementación en C++ del estándar Data Distribution Service del Object Management Group. Antes de las versiones 2.9.1 y 2.6.5, una validación incorrecta de los números de secuencia puede provocar un fallo de aserción alcanzable remotamente. Esto puede bloquear de forma remota cualquier proceso Fast-DDS. Las versiones 2.9.1 y 2.6.5 contienen un parche para este problema.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-08-07 CVE Reserved
- 2023-08-11 CVE Published
- 2024-09-12 EPSS Updated
- 2024-10-09 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-617: Reachable Assertion
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageReceiver.cpp#L1059 | Third Party Advisory | |
https://github.com/eProsima/Fast-DDS/issues/3236 | Third Party Advisory | |
https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cg | Third Party Advisory | |
https://www.debian.org/security/2023/dsa-5481 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eprosima Search vendor "Eprosima" | Fast Dds Search vendor "Eprosima" for product "Fast Dds" | >= 2.6.0 < 2.6.5 Search vendor "Eprosima" for product "Fast Dds" and version " >= 2.6.0 < 2.6.5" | - |
Affected
| ||||||
Eprosima Search vendor "Eprosima" | Fast Dds Search vendor "Eprosima" for product "Fast Dds" | 2.9.0 Search vendor "Eprosima" for product "Fast Dds" and version "2.9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 12.0 Search vendor "Debian" for product "Debian Linux" and version "12.0" | - |
Affected
|