CVE-2025-65865
7.5eProsima · Fast-DDS
An integer overflow in eProsima Fast-DDS v3.3 allows unauthenticated remote attackers to trigger a Denial of Service condition via crafted network input.
Executive summary
A critical integer overflow vulnerability in eProsima Fast-DDS v3.3 permits unauthenticated remote attackers to cause a Denial of Service.
Vulnerability
This is an integer overflow vulnerability located within the input processing logic of Fast-DDS v3.3. The flaw allows an unauthenticated remote attacker to send specifically crafted packets that trigger the overflow, resulting in a system crash or service unavailability.
Business impact
The successful exploitation of this vulnerability results in a Denial of Service, which can disrupt critical operational processes dependent on Fast-DDS middleware. Given the CVSS score of 7.5, the risk is high due to the lack of required authentication and the ease of exploitation over a network. Such service interruptions can lead to significant downtime for dependent industrial or robotic systems.
Remediation
Immediate Action: Consult the official eProsima security advisories to determine if a patch or configuration workaround is available for version 3.3.
Proactive Monitoring: Monitor network traffic for malformed or unusually large packets directed at Fast-DDS ports and review system logs for recurring service crashes or memory error exceptions.
Compensating Controls: Implement network segmentation and firewall rules to restrict access to the Fast-DDS service to only authorized and trusted IP addresses.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the GitHub references provided by the researcher.
Analyst recommendation
Organizations utilizing eProsima Fast-DDS v3.3 must prioritize this vulnerability due to its high severity and the availability of public proof-of-concept code. Administrators should restrict network exposure immediately while awaiting official vendor patches to prevent potential service disruption.