CVE-2023-37915 is a high-severity denial-of-service vulnerability affecting OpenDDS, an open-source C++ implementation of the OMG Data Distribution Service. Attackers can remotely crash OpenDDS processes by sending a specially crafted DATA submessage containing a malformed PID_PROPERTY_LIST during participant discovery. This unauthenticated attack requires low complexity and results in high availability impact, with no confidentiality or integrity impact. While no active exploitation or public exploit code is known, and community discussion is minimal, users are strongly advised to upgrade to OpenDDS version 3.25 to mitigate this risk, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.23.1CPE matchmatch criteria | cpe:2.3:a:objectcomputing:opendds:3.23.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.