CVE-2021-38487

RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rti:connext_dds_micro:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_secure:*:*:*:*:*:*:*:*

History

23 Jun 2025, 12:15

Type Values Removed Values Added
Summary (en) RTI Connext DDS Professional, Connext DDS Secure versions 4.2x to 6.1.0, and Connext DDS Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure. (en) RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.
CVSS v2 : 6.4
v3 : 7.5
v2 : 6.4
v3 : 8.2
CWE CWE-923
References
  • () https://www.rti.com/vulnerabilities/#cve-2021-38487 -

05 Feb 2025, 13:26

Type Values Removed Values Added
CPE cpe:2.3:a:rti:connext_dds_professional:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_dds_secure:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_secure:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
First Time Rti connext Secure
Rti connext Professional

21 Nov 2024, 06:17

Type Values Removed Values Added
References () https://support.rti.com/s/login/?ec=302&startURL=%2Fs%2F - Permissions Required, Vendor Advisory () https://support.rti.com/s/login/?ec=302&startURL=%2Fs%2F - Permissions Required, Vendor Advisory
References () https://www.cisa.gov/uscert/ics/advisories/icsa-21-315-02 - Third Party Advisory, US Government Resource () https://www.cisa.gov/uscert/ics/advisories/icsa-21-315-02 - Third Party Advisory, US Government Resource
CVSS v2 : 6.4
v3 : 9.1
v2 : 6.4
v3 : 7.5

Information

Published : 2022-05-05 17:15

Updated : 2025-06-23 12:15


NVD link : CVE-2021-38487

Mitre link : CVE-2021-38487

CVE.ORG link : CVE-2021-38487


JSON object : View

Products Affected

rti

  • connext_dds_micro
  • connext_secure
  • connext_professional
CWE
CWE-406

Insufficient Control of Network Message Volume (Network Amplification)

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints