CVE-2019-15136
UnknownEPSS 1.40%
Last modified
CVE-2019-15136 is a vulnerability of currently unknown severity. The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partition.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partition.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eprosima | Fast-Rtps | <= 1.9.0 |
References
- https://arxiv.org/abs/1908.05310Third Party Advisory
- https://github.com/eProsima/Fast-RTPS/issues/443Patch, Third Party Advisory
- https://arxiv.org/abs/1908.05310Third Party Advisory
- https://github.com/eProsima/Fast-RTPS/issues/443Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15136?
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partition.
How severe is CVE-2019-15136?
Severity scoring for CVE-2019-15136 is pending analysis. The EPSS model estimates a 1.40% probability of exploitation in the next 30 days.
How do I fix CVE-2019-15136?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-15130The Recruitment module in Humanica Humatrix 7 1.0.0.203 and …
- CVE-2019-15131In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8,…9.8
- CVE-2019-15132Zabbix through 4.4.0alpha1 allows User Enumeration. With log…5.3
- CVE-2019-15133In GIFLIB before 2019-02-16, a malformed GIF file triggers a…6.5
- CVE-2019-15134RIOT through 2019.07 contains a memory leak in the TCP imple…
- CVE-2019-15135The handshake protocol in Object Management Group (OMG) DDS …
- CVE-2019-15137The Access Control plugin in eProsima Fast RTPS through 1.9.…
- CVE-2019-15138The html-pdf package 2.2.0 for Node.js has an arbitrary file…7.5
- CVE-2019-15139The XWD image (X Window System window dumping file) parsing …
- CVE-2019-1514Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-15140coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attac…
- CVE-2019-15141WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 …6.5
Are you affected by CVE-2019-15136?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
