Executive brief
RTI Connext Professional is a software framework used for sharing data between different applications and devices in real-time systems. A security flaw in its Web Integration Service component could allow an attacker to cause a system crash or bypass security filters by sending specially crafted data. This could lead to service outages or the failure of critical data filtering mechanisms in industrial or enterprise environments.
Technical details
A 'Classic Buffer Overflow' (CWE-120) exists in the Web Integration Service component of RTI Connext Professional. The vulnerability is caused by a buffer copy operation that does not properly check the size of the input, leading to memory corruption. An unauthenticated attacker can exploit this over the network to cause a 'Filter Failure' or a denial-of-service (DoS) condition. The issue affects multiple versions across the 6.1.x, 7.0.x, and 7.4.x release branches. Users are advised to update to patched versions such as 7.3.1.3 or later as specified in the vendor's advisory.
Affected products
- RTI Connext Professional (Web Integration Service) 7.4.0 before 7.*, 7.0.0 before 7.3.1.3, 6.1.2 before 6.1.*
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory