Insecure Topic Name Matching in eProsima Fast RTPS Access Control Plugin

Insecure Topic Name Matching in eProsima Fast RTPS Access Control Plugin

CVE-2019-15137 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:N

The Access Control plugin in eProsima Fast RTPS through 1.9.0 allows fnmatch pattern matches with topic name strings (instead of the permission expressions themselves), which can lead to unintended connections between participants in a Data Distribution Service (DDS) network.

Learn more about our Network Penetration Testing.