CVE-2024-30916

An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted max_samples parameter in DurabilityService QoS component.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*

History

10 Feb 2025, 23:15

Type Values Removed Values Added
CWE CWE-20

09 Jan 2025, 15:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CPE cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
References () https://github.com/eProsima/Fast-DDS/issues/4609 - () https://github.com/eProsima/Fast-DDS/issues/4609 - Exploit, Issue Tracking
First Time Eprosima
Eprosima fast Dds
CWE NVD-CWE-noinfo

21 Nov 2024, 09:12

Type Values Removed Values Added
References () https://github.com/eProsima/Fast-DDS/issues/4609 - () https://github.com/eProsima/Fast-DDS/issues/4609 -

11 Apr 2024, 12:47

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en eProsima FastDDS v.2.14.0 y anteriores que permite a un atacante local provocar una denegación de servicio (DoS) y obtener información confidencial a través de un parámetro max_samples manipulado en el componente DurabilityService QoS.

11 Apr 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-11 06:15

Updated : 2025-02-10 23:15


NVD link : CVE-2024-30916

Mitre link : CVE-2024-30916

CVE.ORG link : CVE-2024-30916


JSON object : View

Products Affected

eprosima

  • fast_dds
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation