CVE-2025-65865

7.5

eProsima · Fast-DDS

An integer overflow in eProsima Fast-DDS v3.3 allows unauthenticated remote attackers to trigger a Denial of Service condition via crafted network input.

Executive summary

A critical integer overflow vulnerability in eProsima Fast-DDS v3.3 permits unauthenticated remote attackers to cause a Denial of Service.

Vulnerability

This is an integer overflow vulnerability located within the input processing logic of Fast-DDS v3.3. The flaw allows an unauthenticated remote attacker to send specifically crafted packets that trigger the overflow, resulting in a system crash or service unavailability.

Business impact

The successful exploitation of this vulnerability results in a Denial of Service, which can disrupt critical operational processes dependent on Fast-DDS middleware. Given the CVSS score of 7.5, the risk is high due to the lack of required authentication and the ease of exploitation over a network. Such service interruptions can lead to significant downtime for dependent industrial or robotic systems.

Remediation

Immediate Action: Consult the official eProsima security advisories to determine if a patch or configuration workaround is available for version 3.3.

Proactive Monitoring: Monitor network traffic for malformed or unusually large packets directed at Fast-DDS ports and review system logs for recurring service crashes or memory error exceptions.

Compensating Controls: Implement network segmentation and firewall rules to restrict access to the Fast-DDS service to only authorized and trusted IP addresses.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the GitHub references provided by the researcher.

Analyst recommendation

Organizations utilizing eProsima Fast-DDS v3.3 must prioritize this vulnerability due to its high severity and the availability of public proof-of-concept code. Administrators should restrict network exposure immediately while awaiting official vendor patches to prevent potential service disruption.

More eProsima CVEs

Sources