RTI Connext Professional Out-of-Bounds Read and Write Vulnerability in Recording Service

Vulnerability

A vulnerability allowing out-of-bounds read and write operations has been identified in RTI Connext Professional's Recording Service. This issue can lead to buffer overflows and overreads. The vulnerability is present in Connext Professional versions 7.4.0 prior to 7.5.0, 7.0.0 prior to 7.3.0.7, 6.1.0 prior to 6.1.2.23, and 6.0.0 prior to 6.0.1.42.

Impact

Exploitation of this vulnerability could cause memory corruption, leading to data corruption or application crashes. The vulnerability is only exploitable under certain conditions, such as winning a race condition or when the rollover feature is set to change files based on size, potentially allowing exploitation through a compromised local file system or by publishing data over the network.

Remediation

To mitigate this vulnerability, it is recommended to protect access to the local file system where Recording Service stores data, and to use Security for topics accepted by Recording Service.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.9
exploitability
4.5
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.