CNNVD-202509-3665 Information

CNNVD ID

CNNVD-202509-3665

CVE-2025-4582

  • CNNVD Published: 2025-09-23

Description (Chinese)

RTI Connext Professional是美国RTI公司的一个专为满足工业物联网 (IIoT) 的苛刻要求而设计的连接平台。 RTI Connext Professional 7.6.0之前版本、7.3.0.8之前版本、6.1.2.26之前版本、6.0及之前版本、5.3及之前版本和5.2及之前版本存在安全漏洞,该漏洞源于缓冲区过度读取和差一错误,可能导致文件操作。

Description (English)

RTI Connexional is a connecting platform designed by the United States company RTI to meet the demanding requirements of the Industrial Networking (IIOT). There is a security loophole in the previous version of RTI Connext Environmental 7.6.0, the previous version of 7.3.0.8, the previous version of 6.1.2.2.26, the previous version of 6.0 and the previous version of 5.3 and the previous version of 5.2 and previous versions, which stems from overreading and an error in the buffer zone, which may lead to document operations.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

rubygems

Published

2025-09-23

Last Modified

2026-02-24

References

https://www.rti.com/vulnerabilities/#cve-2025-4582

Patch

https://community.rti.com/static/documentation/connext-dds/current/doc/vulnerabilities/#cve-2025-8410

Share on: