Ad

CVE-2025-24807

MEDIUM CVSS 4.0: 4.5 EPSS 0.08%
Updated Feb 21, 2025
Eprosima
Parameter Value
CVSS 4.5 (MEDIUM)
Affected Versions 2.10.0 — 3.1.2
Fixed In 2.6.10
Type CWE-345 (Insufficient Verification of Data)
Vendor Eprosima
Public PoC No

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0, per design, PermissionsCA is not full chain validated, nor is the expiration date validated. Access control plugin validates only the S/MIME signature which causes an expired PermissionsCA to be taken as valid.

Even though this issue is responsible for allowing `governance/permissions` from an expired PermissionsCA and having the system crash when PermissionsCA is not self-signed and contains the full-chain, the impact is low. Versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0 contain a fix for the issue.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 5

Configuration From (including) Up to (excluding)
Eprosima Fast_Dds
cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
2.6.10
Eprosima Fast_Dds
cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
2.10.0 2.10.7
Eprosima Fast_Dds
cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
2.14.0 2.14.5
Eprosima Fast_Dds
cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
3.0.0 3.0.2
Eprosima Fast_Dds
cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
3.1.0 3.1.2