Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
References
Configurations
History
06 Jan 2026, 17:42
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://eclipse.com - Product | |
| References | () https://gist.github.com/lkloliver/669e15bc7e6194133e4ee1026ce157e6 - Third Party Advisory | |
| References | () https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/ddsrt/src/time/posix/time.c#L28 - Product | |
| References | () https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/security/builtin_plugins/authentication/src/auth_utils.c#L84 - Product | |
| CPE | cpe:2.3:a:eclipse:cyclone_data_distribution_service:*:*:*:*:*:*:*:* | |
| First Time |
Eclipse cyclone Data Distribution Service
Eclipse |
23 Dec 2025, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-23 16:16
Updated : 2026-01-06 17:42
NVD link : CVE-2025-67109
Mitre link : CVE-2025-67109
CVE.ORG link : CVE-2025-67109
JSON object : View
Products Affected
eclipse
- cyclone_data_distribution_service
CWE
CWE-298
Improper Validation of Certificate Expiration
