CVE-2023-50257
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2023-50257 affects eProsima Fast DDS (formerly Fast RTPS), a C++ implementation of the Data Distribution Service standard. The vulnerability exists in versions prior to 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7, dating back to the initial commit of the SecurityManager.cpp code on Nov 8, 2016 (GitHub Advisory).

Technical details

The vulnerability stems from unencrypted data (p[UD]) and guid values used for node disconnection in RTPS packets, even when SROS2 security is applied. The issue exists in the SecurityManager's initialization and handshake process, where the SecurityManager::init function only executes once based on the Participant GUID when initially running the node (GitHub Advisory). The vulnerability has been assigned a CVSS v3.1 base score of 9.6 CRITICAL with vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (NVD).

Impact

An attacker can forcibly disconnect a Subscriber and prevent it from reconnecting. When the attacker sends a disconnection packet (data(p[UD])) to the Global Data Space (239.255.0.1:7400) using a captured Publisher ID, all Subscribers connected to the Publisher will lose their connection and stop receiving data. Furthermore, continuous transmission of these disconnection packets prevents Subscribers from establishing new connections (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7. Users should upgrade to these or later versions to protect against this vulnerability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22776HIGH8.7
  • Linux DebianLinux Debian
  • cpp-httplib
NoNoJan 12, 2026
CVE-2026-22801MEDIUM6.8
  • OpenJDK JDKOpenJDK JDK
  • java-21-openjdk-demo-fastdebug
NoYesJan 12, 2026
CVE-2026-22695MEDIUM6.1
  • OpenJDK JDKOpenJDK JDK
  • java-25-openjdk-static-libs
NoYesJan 12, 2026
CVE-2026-22251MEDIUM5.3
  • PythonPython
  • wlc
NoYesJan 12, 2026
CVE-2026-0665N/AN/A
  • Linux DebianLinux Debian
  • qemu
NoNoJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management