CVE-2021-38487
RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.10%
- CWE
- CWE-406, CWE-923
- Published
- 2022-05-05
- Last modified
- 2026-03-13
Affected products
- RTI Connext Professional
- RTI Connext Micro
- RTI Connext Micro
- RTI Connext Micro
Weakness type
Related vulnerabilities
- CVE-2022-0028 — PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering
- CVE-2021-38135 — Possible External service interaction Vulnerability in OpenText iManager
- CVE-2024-25015 — IBM MQ denial of service
- CVE-2021-43547 — TwinOaks Computing CoreDX DDS Secure Network Amplification
- CVE-2021-38425 — eProsima Fast DDS Network Amplification
- CVE-2026-54609 — QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
- CVE-2021-38429 — OCI OpenDDS Secure Network Amplification
- CVE-2026-45557 — Technitium DNS Server excessive DNSSEC requests