CVE-2025-62601 is a heap buffer overflow vulnerability affecting eprosima Fast DDS versions prior to 3.4.1, 3.3.1, and 2.6.11, specifically when security mode is enabled. An unauthenticated attacker can remotely terminate the Fast DDS process by manipulating the DATA Submessage within an SPDP packet, leading to a 32-bit integer overflow and subsequent heap buffer overflow. With a CVSS score of 7.5 (HIGH), this vulnerability has a network attack vector, low attack complexity, and high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2.6.11CPE match | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.3.1CPE match | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.1CPE match | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* | ||
< 2.6.11CPE matchmatch criteria | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* | ||
3.4.0CPE matchmatch criteria | cpe:2.3:a:eprosima:fast_dds:3.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.