CVE Vulnerabilities

CVE-2024-30917

Improper Handling of Values

Published: Apr 11, 2024 | Modified: Jun 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io minimus.io echohq.com

An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted history_depth parameter in DurabilityService QoS component.

Weakness

The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.

Affected Software

Name Vendor Start Version End Version
Fast_dds Eprosima * 2.14.0 (including)
Fastdds Ubuntu mantic *

References