CVE-2025-24807

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-24807
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24807.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-24807
Aliases
  • GHSA-w33g-jmm2-8983
Downstream
Published
2025-02-11T15:31:50Z
Modified
2025-10-15T22:53:56.857783Z
Severity
  • 4.5 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Fast DDS does not verify Permissions CA
Details

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0, per design, PermissionsCA is not full chain validated, nor is the expiration date validated. Access control plugin validates only the S/MIME signature which causes an expired PermissionsCA to be taken as valid. Even though this issue is responsible for allowing governance/permissions from an expired PermissionsCA and having the system crash when PermissionsCA is not self-signed and contains the full-chain, the impact is low. Versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0 contain a fix for the issue.

References

Affected packages

Git / github.com/eProsima/Fast-DDS

Affected ranges

Type
GIT
Repo
https://github.com/eProsima/Fast-DDS
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/eProsima/Fast-DDS
Events
Type
GIT
Repo
https://github.com/eProsima/Fast-DDS
Events
Type
GIT
Repo
https://github.com/eProsima/Fast-DDS
Events
Type
GIT
Repo
https://github.com/eProsima/Fast-DDS
Events

Affected versions

2.*

2.0.0-beta
2.0.0-rc

Other

Discovery-Time_Data_Typing

v0.*

v0.5.2

v1.*

v1.0.0
v1.0.0.a
v1.0.6
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.0-2
v1.8.1
v1.9.0
v1.9.0-beta
v1.9.0-beta-2

v2.*

v2.1.0
v2.2.0
v2.3.0-1
v2.3.0-api