Executive brief
RTI Connext Professional, a widely used connectivity framework for industrial and mission-critical systems, contains a security flaw in its Security Plugins. This vulnerability allows an attacker to bypass authentication for critical functions, enabling them to spoof or fake the source of data within the system. This could lead to unauthorized commands being accepted as legitimate, potentially compromising the integrity of operations and data in automated environments.
Technical details
A Missing Authentication for Critical Function vulnerability (CWE-306) exists in the Security Plugins of RTI Connext Professional. The flaw allows an attacker with low privileges to bypass authentication checks for critical operations, specifically enabling the faking of data sources. The attack vector is network-based and requires low privileges, though it is categorized with a 'Physical' or 'Provable' attack threshold in CVSS 4.0 terminology (AT:P). Successful exploitation allows an attacker to inject high-integrity data as if it originated from a trusted source. Affected versions include various releases across the 5.x, 6.x, and 7.x branches; users are advised to upgrade to the respective fixed versions (e.g., 7.7.0 or 7.3.1.3).
Affected products
- RTI Connext Professional (Security Plugins) 7.4.0 before 7.7.0, 7.0.0 before 7.3.1.3, 6.1.0 before 6.1.*, 6.0.0 before 6.0.*, 5.3.0 before 5.3.*
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory