Executive brief
RTI Connext Professional is a connectivity framework used in industrial and mission-critical systems to manage real-time data exchange. A security flaw in its core libraries could allow an attacker to read more data than intended from the system's memory. This could lead to the exposure of sensitive information or cause the software to crash, potentially disrupting critical operations.
Technical details
A buffer over-read vulnerability (CWE-125/CWE-126) exists in the Core Libraries of RTI Connext Professional. The flaw occurs when the software reads data past the end of the intended buffer, which can be triggered by a remote attacker over the network without authentication. Successful exploitation can result in the disclosure of sensitive information from memory or a partial denial-of-service (DoS) condition. The issue affects multiple versions across the 4.x, 5.x, 6.x, and 7.x release branches; users are advised to upgrade to the respective patched versions (e.g., 7.7.0, 7.3.1.1, or 6.1.2.34) as specified in the vendor advisory.
Affected products
- RTI Connext Professional (Core Libraries) 7.4.0 before 7.7.0, 7.0.0 before 7.3.1.1, 6.1.0 before 6.1.2.34, 6.0.0 before 6.0.*, 5.3.0 before 5.3.*, 4.3x before 5.2.*
Timeline
- 2026-04-01: disclosed
- 2026-04-01: advisory
- 2026-06-17: other: Advisory updated with refined version ranges.