CVE-2025-63548

7.5

Eprosima · Micro-XREC-DDS Agent

A denial of service vulnerability in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows remote unauthenticated attackers to crash the service.

Executive summary

A denial of service vulnerability in the Eprosima Micro-XREC-DDS Agent allows unauthenticated remote attackers to disrupt system availability.

Vulnerability

This is a denial of service vulnerability triggered by sending a specially crafted packet containing an invalid value in a Boolean field, which can be exploited by an unauthenticated remote attacker.

Business impact

A successful exploitation of this vulnerability can cause critical system downtime and service disruption for applications relying on the affected DDS agent. With a CVSS score of 7.5, the risk is classified as high due to the low complexity of the attack and the lack of authentication required to impact availability.

Remediation

Immediate Action: Apply vendor security updates as soon as they become available from Eprosima, and restrict network access to trusted hosts if patches are delayed.

Proactive Monitoring: Monitor network traffic for anomalous packet structures and check agent logs for unexpected service crashes or restarts.

Compensating Controls: Deploy network firewalls or intrusion detection systems to filter invalid protocol packets directed at the agent.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept reference exists via the GitHub advisory link provided in the record.

Analyst recommendation

Organizations utilizing the Eprosima Micro-XREC-DDS Agent should monitor the official vendor repository for patches immediately. In the interim, implement strict network segmentation to limit exposure to untrusted networks and prevent potential denial of service attacks.

More Eprosima CVEs

Sources