Connext Professional

Vendor:

First CVE: May 5, 2022 · Active for 4 years

32
Total CVEs
More Total CVEs than 96% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Connext Professional over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2022
4 years ago
Most Recent CVE
Jun 17, 2026
37 days ago

CVE Severity & Scoring

Connext Professional32 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local13 (40.6%)
Network19 (59.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (93.8%)
High2 (6.3%)
Unknown0 (0.0%)
User Interaction
None28 (87.5%)
Unknown0 (0.0%)
Required4 (12.5%)
Privileges Required
Low14 (43.8%)
High0 (0.0%)
None18 (56.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 b
Jun 17, 20269.136NONO
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before
Jun 17, 20268.135NONO
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext
Apr 30, 20269.132NONO
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.
Sep 23, 20259.132NONO
Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffer
Jun 17, 20268.131NONO
Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.This issue affects Connext Professional: from 7.4
Jun 17, 20268.131NONO
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Over
Jun 17, 20266.529NONO
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Obse
Apr 1, 20269.129NONO
RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices wi
May 5, 20229.129NONO
RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocating the buffer, which may result in a buffer overflow.
May 5, 20229.829NONO

Exploit Exposure

Signals from CVEs in this product scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (32 CVEs).

Media Mentions

Signals from CVEs in this product scope (32 CVEs).

Top CNAs Publishing CVEs For Connext Professional

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.1.017.30.2%00
5.3.1.4017.10.1%00