CVE-2024-10838 is a critical integer underflow vulnerability affecting Eclipse Cyclone DDS, allowing unauthenticated attackers to read out-of-bounds heap memory during deserialization. This can lead to the exposure of sensitive data, memory layout information, and potentially cause denial of service or thread crashes. With a CVSS score of 9.1, it presents a significant risk, though there is currently no public exploit code, active exploitation, or community discussion reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.10.5CPE matchmatch criteria | cpe:2.3:a:eclipse:cyclone_data_distribution_service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.