CVE-2025-24807

Source
https://cve.org/CVERecord?id=CVE-2025-24807
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24807.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-24807
Aliases
  • GHSA-w33g-jmm2-8983
Downstream
Published
2025-02-11T15:31:50.337Z
Modified
2026-04-02T12:45:59.118398Z
Severity
  • 4.5 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Fast DDS does not verify Permissions CA
Details

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0, per design, PermissionsCA is not full chain validated, nor is the expiration date validated. Access control plugin validates only the S/MIME signature which causes an expired PermissionsCA to be taken as valid. Even though this issue is responsible for allowing governance/permissions from an expired PermissionsCA and having the system crash when PermissionsCA is not self-signed and contains the full-chain, the impact is low. Versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0 contain a fix for the issue.

Database specific
{
    "cwe_ids": [
        "CWE-345"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24807.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/eprosima/fast-dds

Affected ranges

Type
GIT
Repo
https://github.com/eprosima/fast-dds
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.6.10"
        }
    ]
}
Type
GIT
Repo
https://github.com/eprosima/fast-dds
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.7.0"
        },
        {
            "fixed": "2.10.7"
        }
    ]
}
Type
GIT
Repo
https://github.com/eprosima/fast-dds
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.11.0"
        },
        {
            "fixed": "2.14.5"
        }
    ]
}
Type
GIT
Repo
https://github.com/eprosima/fast-dds
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.0.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/eprosima/fast-dds
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.1.0"
        },
        {
            "fixed": "3.1.2"
        }
    ]
}

Affected versions

2.*
2.0.0-beta
2.0.0-rc
2.0.1-rc
Other
Discovery-Time_Data_Typing
TypeLookup_Service
XTYPES_v1
v0.*
v0.3.0
v0.3.1
v0.4.0
v0.5.0
v0.5.1
v0.5.2
v1.*
v1.0.0
v1.0.0.a
v1.0.6
v1.1.0
v1.10.0
v1.10.1
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.8.0
v1.8.0-2
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.9.0
v1.9.0-beta
v1.9.0-beta-2
v1.9.1
v1.9.2
v1.9.3
v1.9.3P1
v1.9.4
v1.9.5
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.10.0
v2.10.0-rc1
v2.10.1
v2.10.1-rc1
v2.10.2
v2.10.3
v2.10.4
v2.10.4-realsense
v2.10.5
v2.10.6
v2.10.7
v2.11.0
v2.11.1
v2.11.2
v2.11.3
v2.12.0
v2.12.0rc
v2.12.0rc2
v2.12.0rc3
v2.12.1
v2.12.2
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.13.4
v2.13.5
v2.13.6
v2.14.0
v2.14.1
v2.14.2
v2.14.3
v2.14.4
v2.14.5
v2.14.6
v2.2.0
v2.2.1
v2.3.0
v2.3.0-1
v2.3.0-api
v2.3.01
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.4.0
v2.4.1
v2.4.2
v2.5.0
v2.5.1
v2.5.2
v2.6.0
v2.6.1
v2.6.11
v2.6.2
v2.6.3
v2.6.4
v2.6.5
v2.6.6
v2.6.7
v2.6.8
v2.6.9
v2.7.0
v2.7.1
v2.7.2
v2.8.0
v2.8.1
v2.8.2
v2.9.0
v2.9.1
v2.9.2
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.2.0
v3.2.0-vulcanexus
v3.2.1
v3.2.2
v3.2.3
v3.3.0
v3.3.1
v3.4.0
v3.4.1
v3.4.2
v3.5.0
v3.5.0.0
v3.6.0
v3.6.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24807.json"