CVE-2025-67109
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/12/2025
Last modified:
23/12/2025
Description
Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- http://eclipse.com
- https://gist.github.com/lkloliver/669e15bc7e6194133e4ee1026ce157e6
- https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/ddsrt/src/time/posix/time.c#L28
- https://github.com/eclipse-cyclonedds/cyclonedds/blob/master/src/security/builtin_plugins/authentication/src/auth_utils.c#L84



