Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

RTI — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting RTI. AI-powered Chinese analysis, POCs, and references for each vulnerability.

RTI, primarily known for its Real-Time Publish-Subscribe (DDS) middleware, facilitates critical data exchange in aerospace, defense, and industrial automation sectors. With twenty-five recorded Common Vulnerabilities and Exposures, the software has historically exhibited significant security flaws, predominantly involving remote code execution and cross-site scripting. These vulnerabilities often stem from insufficient input validation and improper access controls within the communication protocols. Notably, several incidents have highlighted risks related to privilege escalation, allowing unauthorized users to gain elevated system access. The complexity of DDS implementations frequently exacerbates these issues, as misconfigurations can expose sensitive operational data to external threats. While essential for real-time systems, the middleware’s security posture requires rigorous patching and strict network segmentation to mitigate the potential for exploitation in high-stakes environments.

CVE ID Title CVSS Severity Published
CVE-2024-52066 Potential stack corruption in Routing Service when using a malicious XML configuration document — Connext Professional CWE-120 9.1 - 2024-12-13
CVE-2024-52065 Potential stack buffer write overflow in Persistence Service while parsing malicious environment variable on non-Windows systems — Connext Professional CWE-120 8.4 - 2024-12-13
CVE-2024-52064 Potential stack buffer write overflow in Connext applications while parsing malicious license file — Connext Professional CWE-120 9.1 - 2024-12-13
CVE-2024-52063 Potential stack buffer write overflow in Connext applications while parsing malicious XML types document — Connext Professional CWE-120 9.8 - 2024-12-13
CVE-2024-52062 Potential stack buffer write overflow in Connext applications while parsing malicious XML types document — Connext Professional CWE-120 9.1 - 2024-12-13
CVE-2024-52061 Potential stack buffer overflow when parsing an XML type — Connext Professional CWE-120 9.8 - 2024-12-13
CVE-2024-52060 Potential stack overflow when using XML configuration file referencing environment variables — Connext Professional CWE-120 9.8 - 2024-12-13
CVE-2024-52059 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags. — Connext Professional CWE-120 6.9 Medium 2024-12-13
CVE-2024-52058 Potential arbitrary command execution in System Designer while parsing malicious HTTP/REST requests — Connext Professional CWE-78 8.8 - 2024-12-13
CVE-2024-52057 Potential arbitrary SQL query execution in Queuing Service while parsing malicious remote commands or configuration files — Connext Professional CWE-89 9.8 - 2024-12-13
CVE-2021-38435 RTI Connext DDS Professional and Connext DDS Secure Incorrect Calculation of Buffer Size — Connext DDS Professional CWE-131 6.6 Medium 2022-05-05
CVE-2021-38433 RTI Connext DDS Professional and Connext DDS Secure Stack-based Buffer Overflow — Connext DDS Professional CWE-121 6.6 Medium 2022-05-05
CVE-2021-38427 RTI Connext DDS Professional and Connext DDS Secure Stack-based Buffer Overflow — Connext DDS Professional CWE-121 6.6 Medium 2022-05-05
CVE-2021-38487 Potential Network Amplification and Information Exposure in RTI Connext Professional and Connext Micro — Connext Professional CWE-406 8.2 High 2022-05-05

This page lists every published CVE security advisory associated with RTI. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.