RTI Connext Professional是美国RTI公司的一个专为满足工业物联网 (IIoT) 的苛刻要求而设计的连接平台。 RTI Connext Professional存在安全漏洞,该漏洞源于使用的特殊元素的不当中和,会导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RTI | Connext Professional | 7.0.0 ~ 7.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-52059 | 6.9 MEDIUM | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer |
| CVE-2024-52063 | Potential stack buffer write overflow in Connext applications while parsing malicious XML | |
| CVE-2024-52060 | Potential stack overflow when using XML configuration file referencing environment variabl | |
| CVE-2024-52062 | Potential stack buffer write overflow in Connext applications while parsing malicious XML | |
| CVE-2024-52064 | Potential stack buffer write overflow in Connext applications while parsing malicious lice | |
| CVE-2024-52061 | Potential stack buffer overflow when parsing an XML type | |
| CVE-2024-52066 | Potential stack corruption in Routing Service when using a malicious XML configuration doc | |
| CVE-2024-52065 | Potential stack buffer write overflow in Persistence Service while parsing malicious envir | |
| CVE-2024-52058 | Potential arbitrary command execution in System Designer while parsing malicious HTTP/REST |
No comments yet