RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.
History

Mon, 23 Jun 2025 12:15:00 +0000

Type Values Removed Values Added
Description RTI Connext DDS Professional, Connext DDS Secure versions 4.2x to 6.1.0, and Connext DDS Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure. RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.
Title RTI Connext DDS Professional and Connext DDS Secure Network Amplification Potential Network Amplification and Information Exposure in RTI Connext Professional and Connext Micro
Weaknesses CWE-923
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Rti connext Professional
Rti connext Secure
CPEs cpe:2.3:a:rti:connext_dds_professional:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_dds_secure:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_secure:*:*:*:*:*:*:*:*
Vendors & Products Rti connext Dds Professional
Rti connext Dds Secure
Rti connext Professional
Rti connext Secure

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2022-05-05T15:18:41.000Z

Updated: 2025-06-23T12:13:04.553Z

Reserved: 2021-08-10T00:00:00.000Z

Link: CVE-2021-38487

cve-icon Vulnrichment

Updated: 2024-08-04T01:44:22.948Z

cve-icon NVD

Status : Modified

Published: 2022-05-05T17:15:09.857

Modified: 2025-06-23T12:15:21.893

Link: CVE-2021-38487

cve-icon Redhat

No data.