CVE-2025-24807

EUVD-2025-3949
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0, per design, PermissionsCA is not full chain validated, nor is the expiration date validated. Access control plugin validates only the S/MIME signature which causes an expired PermissionsCA to be taken as valid. Even though this issue is responsible for allowing `governance/permissions` from an expired PermissionsCA and having the system crash when PermissionsCA is not self-signed and contains the full-chain, the impact is low. Versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0 contain a fix for the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 9.59%
Affected Products (NVD)
VendorProductVersion
eprosimafast_dds
𝑥
< 2.6.10
eprosimafast_dds
2.10.0 ≤
𝑥
< 2.10.7
eprosimafast_dds
2.14.0 ≤
𝑥
< 2.14.5
eprosimafast_dds
3.0.0 ≤
𝑥
< 3.0.2
eprosimafast_dds
3.1.0 ≤
𝑥
< 3.1.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
fastdds
bookworm
no-dsa
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
sid
3.3.0+ds-3
fixed
trixie
3.1.2+ds-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fastdds
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage