CVE-2025-63547

7.5

Eprosima · Micro-XRCE-DDS-Agent

A denial of service vulnerability in Eprosima Micro-XRCE-DDS-Agent v.3.0.1 allows remote attackers to crash the service via a crafted packet targeting the MTU length field.

Executive summary

An unauthenticated remote denial of service vulnerability exists in Eprosima Micro-XRCE-DDS-Agent, posing a significant risk to system availability.

Vulnerability

This vulnerability is a denial of service flaw triggered by sending a specially crafted packet to the affected agent. An unauthenticated remote attacker can exploit this by manipulating the MTU length field, causing the service to terminate unexpectedly.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk to service availability. Successful exploitation results in the disruption of critical communication services, which could lead to significant operational downtime for systems relying on the DDS agent for data transmission.

Remediation

Immediate Action: Monitor official Eprosima security advisories and repository updates for the release of a patch addressing this specific issue in the Micro-XRCE-DDS-Agent.

Proactive Monitoring: Inspect system logs and network traffic for repeated or anomalous packets targeting the agent, which may indicate attempts to trigger the denial of service condition.

Compensating Controls: Deploy network-level access controls to restrict traffic to the Micro-XRCE-DDS-Agent to known, trusted origins, thereby limiting the exposure of the vulnerable interface to potential attackers.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for remote disruption, organizations utilizing Eprosima Micro-XRCE-DDS-Agent should prioritize restricting network access to the agent. Administrators must remain vigilant for vendor-provided security patches and apply them as soon as they become available to restore system integrity and availability.

More Eprosima CVEs

Sources