Home

Description

Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.

PUBLISHED Reserved 2025-12-08 | Published 2025-12-23 | Updated 2025-12-23 | Assigner mitre

References

eclipse.com

github.com/...ds/blob/master/src/ddsrt/src/time/posix/time.c

github.com/...uiltin_plugins/authentication/src/auth_utils.c

gist.github.com/lkloliver/669e15bc7e6194133e4ee1026ce157e6

cve.org (CVE-2025-67109)

nvd.nist.gov (CVE-2025-67109)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.