CVE-2025-67109
10.0CRITICALImproper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
Publicado: 12/23/2025Actualizado: 1/6/2026
Descripción
Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
Análisis IAImpulsado por IA
Productos Afectados
eclipsecyclone_data_distribution_service
Referencias
- http://eclipse.comProduct
- https://gist.github.com/lkloliver/669e15bc7e6194133e4ee1026ce157e6Third Party Advisory
- https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/ddsrt/src/time/posix/time.c#L28Product
- https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/security/builtin_plugins/authentication/src/auth_utils.c#L84Product