CVE-2019-15137
Summary
| CVE | CVE-2019-15137 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-18 16:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | The Access Control plugin in eProsima Fast RTPS through 1.9.0 allows fnmatch pattern matches with topic name strings (instead of the permission expressions themselves), which can lead to unintended connections between participants in a Data Distribution Service (DDS) network. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [1908.05310] Network Reconnaissance and Vulnerability Excavation of Secure DDS Systems | MISC | arxiv.org | Third Party Advisory |
| Misuse of fnmatch used by DDS Security Access Control [5346] · Issue #441 · eProsima/Fast-DDS · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.