Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
References
Configurations
History
06 Jan 2026, 17:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:eclipse:cyclone_data_distribution_service:*:*:*:*:*:*:*:* | |
| First Time |
Eclipse cyclone Data Distribution Service
Eclipse |
|
| References | () http://eclipse.com - Product | |
| References | () https://gist.github.com/lkloliver/669e15bc7e6194133e4ee1026ce157e6 - Third Party Advisory | |
| References | () https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/ddsrt/src/time/posix/time.c#L28 - Product | |
| References | () https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/security/builtin_plugins/authentication/src/auth_utils.c#L84 - Product |
23 Dec 2025, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-23 16:16
Updated : 2026-01-06 17:42
NVD link : CVE-2025-67109
Mitre link : CVE-2025-67109
CVE.ORG link : CVE-2025-67109
JSON object : View
Products Affected
eclipse
- cyclone_data_distribution_service
CWE
CWE-298
Improper Validation of Certificate Expiration
