Vulnerability Details CVE-2021-38445
OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associated data, which may allow an attacker to remotely execute arbitrary code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.3%
CVSS Severity
CVSS v3 Score 7.0
CVSS v2 Score 7.5
Products affected by CVE-2021-38445
-
cpe:2.3:a:objectcomputing:opendds:-