Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Eprosima

First CVE: Aug 18, 2019Active for: 7 yearsTotal CVEs: 29
50.6
VTI Score
TOP TARGET

Eprosima maintains a focused portfolio centered on the Fast DDS middleware platform, a publish-subscribe messaging implementation widely embedded in robotics, autonomous systems, and real-time distributed applications. Despite the narrow product scope, the vendor ranks among the more prominent in the vulnerability landscape due to the critical role DDS plays in safety-sensitive and networked embedded systems. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety weakness classes including heap-based buffer overflows, out-of-bounds writes, and integer overflows that are characteristic of C/C++ implementations handling untrusted protocol input. The exposure footprint is compact but consequential: a single flaw in the DDS serialization or protocol layer can propagate to all downstream applications and devices that depend on the library. Defenders should track Eprosima advisories closely for deployments in autonomous vehicles, robotics platforms, and industrial control systems, and prioritize patching where DDS handles external or network-sourced messages; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Eprosima over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2019
6 years ago
Most Recent CVE
Feb 3, 2026
171 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-67108CRITICAL
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
Dec 23, 202510.038NONO
CVE-2021-38425CRITICAL
eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic,
May 5, 20229.131NONO
CVE-2025-62799CRITICAL
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a heap buffer ov
Feb 3, 20269.830NONO
CVE-2025-65865HIGH
An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Dec 23, 20257.528NONO
CVE-2023-50716CRITICAL
eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, 2.12.2, 2.11.3, 2
Mar 6, 20249.825NONO
CVE-2025-64438HIGH
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a remotely trigg
Feb 3, 20267.524NONO
CVE-2025-62603HIGH
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ParticipantGenericMessage is the DDS Security control-messag
Feb 3, 20267.524NONO
CVE-2025-62602HIGH
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the securit
Feb 3, 20267.524NONO
CVE-2025-62601HIGH
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the securit
Feb 3, 20267.524NONO
CVE-2025-62600HIGH
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1, wh
Feb 3, 20267.524NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
79%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (10.3%)
Network25 (86.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.4%)
Attack Complexity
Low28 (96.6%)
High1 (3.4%)
Unknown0 (0.0%)
User Interaction
None29 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (10.3%)
High0 (0.0%)
None26 (89.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Eprosima.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Eprosima — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Eprosima's Products

View all 3 CNAs →

Top CWEs