Vulnerability Intelligence Report
Specially crafted RTPS message may cause an OpenDDS application to crash
CVE-2023-23932
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS applications that are exposed to untrusted RTPS network traffic may crash when parsing badly-formed input. This issue has been patched in version 3.23.1.
No Active Exploit Signals
CVSS Base Score
5.3
MEDIUM
Exploitability:3.9
Impact Score:1.5
EPSS Probability:0.74%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-248 ↗CWE-248: Uncaught Exception
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| OpenDDS | OpenDDS | < 3.23.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.738%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2023-01-19T21:12:31 |
| Published | 2023-02-03T20:08:31 |
| Last Updated | 2025-03-10T21:16:50 |
Community Chatter & Buzz