Executive brief
RTI Connext Professional is a middleware platform used for real-time distributed system communication. This vulnerability allows an attacker on the network to intercept and read unencrypted traffic, exposing sensitive data exchanged between Connext-based applications without requiring authentication or special privileges.
Technical details
The vulnerability is a failure to encrypt network communication in the Connext Professional Core Libraries, allowing network sniffing of unprotected traffic. The issue affects versions 7.4.0 through 7.6.x and 7.2.0 through 7.3.0. An attacker positioned on the network (adjacent or same subnet) can passively capture and read Connext communication traffic. No authentication or user interaction is required to exploit this vulnerability; only network access is needed. Patches are available for supported LTS versions through RTI's standard patching process.
Affected products
- RTI Connext Professional 7.4.0 to 7.6.x, 7.2.0 to 7.3.0
Timeline
- 2025-12-16: disclosed
- 2025-12-16: patched: Patches available for 7.7.0 and 7.3.1+