VendorsRticonnext_professionalall versions
Vulnerabilities

Rti Real-Time Innovations (rti) Connext Professional

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

32CVEs
CVE-2021-38435
RTI Connext DDS Professional and Connext DDS Secure Incorrect Calculation of Buffer Size
Published 2022-05-05 · Modified
9.8EPSS 0.014
CVE-2024-52061
Potential stack buffer overflow when parsing an XML type
Published 2024-12-13 · Analyzed
9.8EPSS 0.005
CVE-2024-52057
Potential arbitrary SQL query execution in Queuing Service while parsing malicious remote commands or configuration files
Published 2024-12-13 · Analyzed
9.8EPSS 0.004
CVE-2026-3894
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
Published 2026-06-17 · Modified
9.2EPSS 0.002
CVE-2026-2467
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.
Published 2026-06-17 · Modified
9.2EPSS 0.002
CVE-2021-38487
Potential Network Amplification and Information Exposure in RTI Connext Professional and Connext Micro
Published 2022-05-05 · Modified
9.1EPSS 0.033
CVE-2025-4993
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.
Published 2025-09-23 · Modified
9.1EPSS 0.004
CVE-2025-1255
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.
Published 2025-09-23 · Modified
9.1EPSS 0.004
CVE-2026-4374
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (multiple infrastructure services) allows Serialized Data External Linking, Data Serialization External Entities Blowup.
Published 2026-04-01 · Modified
9.1EPSS 0.002
CVE-2025-14543
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.
Published 2026-04-30 · Modified
9.1EPSS 0.002
CVE-2026-7300
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow.
Published 2026-06-17 · Modified
8.8EPSS 0.003
CVE-2024-52058
Potential arbitrary command execution in System Designer while parsing malicious HTTP/REST requests
Published 2024-12-13 · Analyzed
8.6EPSS 0.006
CVE-2024-52063
Potential stack buffer write overflow in Connext applications while parsing malicious XML types document
Published 2024-12-13 · Analyzed
8.6EPSS 0.003
CVE-2024-52060
Potential stack overflow when using XML configuration file referencing environment variables
Published 2024-12-13 · Analyzed
8.3EPSS 0.003
CVE-2024-52066
Potential stack corruption in Routing Service when using a malicious XML configuration document
Published 2024-12-13 · Analyzed
8.3EPSS 0.003
CVE-2025-10450
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.
Published 2025-12-16 · Modified
8.3EPSS 0.002
CVE-2026-30799
Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.
Published 2026-06-17 · Modified
8.1EPSS 0.003
CVE-2026-2674
Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers.
Published 2026-06-17 · Modified
8.1EPSS 0.002
CVE-2021-38427
RTI Connext DDS Professional and Connext DDS Secure Stack-based Buffer Overflow
Published 2022-05-05 · Modified
7.8EPSS 0.006
CVE-2021-38433
RTI Connext DDS Professional and Connext DDS Secure Stack-based Buffer Overflow
Published 2022-05-05 · Modified
7.8EPSS 0.006
CVE-2025-1253
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.
Published 2025-05-08 · Modified
7.8EPSS 0.002
CVE-2024-52059
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags.
Published 2024-12-13 · Modified
7.8EPSS 0.002
CVE-2024-52062
Potential stack buffer write overflow in Connext applications while parsing malicious XML types document
Published 2024-12-13 · Analyzed
7.8EPSS 0.002
CVE-2025-1254
Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers.
Published 2025-05-08 · Modified
7.7EPSS 0.002
CVE-2025-8410
Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.
Published 2025-09-23 · Modified
7.4EPSS 0.002
CVE-2024-25724
In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the RTI_RoutingService_new, rti::recording::Service, RTI_QueuingService_new, or RTI_CDS_Service_new public APIs; or a compromised local file system containing a malicious XML file.
Published 2024-05-21 · Analyzed
7.3EPSS 0.002
CVE-2024-52064
Potential stack buffer write overflow in Connext applications while parsing malicious license file
Published 2024-12-13 · Analyzed
7.1EPSS 0.002
CVE-2024-52065
Potential stack buffer write overflow in Persistence Service while parsing malicious environment variable on non-Windows systems
Published 2024-12-13 · Analyzed
7.1EPSS 0.002
CVE-2025-1252
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.
Published 2025-05-08 · Modified
7.1EPSS 0.002
CVE-2025-4582
Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers.
Published 2025-09-23 · Modified
7.1EPSS 0.001
CVE-2026-2675
Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.
Published 2026-06-17 · Modified
6.5EPSS 0.002
CVE-2026-2394
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
Published 2026-04-01 · Modified
6.5EPSS 0.002