📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Artificial Intelligence and Technology HIGH 20m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 16h Global apt Critical Infrastructure CRITICAL 16h Global vulnerability Artificial Intelligence and Technology HIGH 20m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 16h Global apt Critical Infrastructure CRITICAL 16h Global vulnerability Artificial Intelligence and Technology HIGH 20m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 16h Global apt Critical Infrastructure CRITICAL 16h
Vulnerabilities

CVE-2025-62602

High
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, m
CWE-122 — Weakness Type
Published: Feb 3, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group
). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an
SPDP packet sent by a publisher causes a heap buffer overflow, resulting in remote termination of Fast-DDS. If the fields
of `PID_IDENTITY_TOKEN` or `PID_PERMISSIONS_TOKEN` in the DATA Submessage are tampered with — specially `readOctetVector`
reads an unchecked `vecsize` that is propagated unchanged into `readData` as the `length` parameter — the attacker-contro
lled `vecsize` can trigger a 32-bit integer overflow during the `length` calculation. That overflow can cause large alloca
tion attempt that quickly leads to OOM, enabling a remotely-triggerable denial-of-service and remote process termination.
Versions 3.4.1, 3.3.1, and 2.6.11 patch the issue.

🤖 AI Executive Summary

Fast DDS versions prior to 3.4.1, 3.3.1, and 2.6.11 contain a critical heap buffer overflow vulnerability in security-enabled mode when processing malformed SPDP packets. An attacker can trigger a 32-bit integer overflow by tampering with PID_IDENTITY_TOKEN or PID_PERMISSIONS_TOKEN fields, causing out-of-memory conditions and remote process termination. This vulnerability affects distributed real-time systems commonly used in industrial IoT, autonomous systems, and critical infrastructure.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 2, 2026 13:17
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations utilizing Fast DDS in critical sectors face significant operational disruption risks. Primary impact areas include: (1) Energy sector (ARAMCO, SABIC) — DDS used in SCADA and industrial control systems for oil/gas operations; (2) Telecommunications (STC, Mobily) — DDS in 5G network infrastructure and real-time signaling; (3) Government critical infrastructure — DDS in command and control systems; (4) Healthcare — DDS in medical device networks and hospital information systems; (5) Aviation and Transportation — DDS in autonomous vehicle and air traffic control systems. Remote denial-of-service capability poses severe availability risks to these sectors.
🏢 Affected Saudi Sectors
Energy (Oil & Gas) Telecommunications Government & Critical Infrastructure Healthcare Aviation & Transportation Industrial Manufacturing Defense & Security
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all systems running Fast DDS versions <3.4.1, <3.3.1, or <2.6.11 using network scanning and software inventory tools
2. Disable or isolate systems with security mode enabled until patching is complete
3. Implement network segmentation to restrict SPDP packet sources to trusted publishers only
4. Monitor for abnormal process terminations and out-of-memory errors in DDS applications

PATCHING GUIDANCE:
1. Upgrade Fast DDS to version 3.4.1, 3.3.1, or 2.6.11 immediately
2. Test patches in non-production environments first
3. Coordinate patching with system owners to minimize downtime
4. Verify patch installation by checking version numbers post-deployment

COMPENSATING CONTROLS (if patching delayed):
1. Implement firewall rules to restrict SPDP multicast traffic (UDP port 7400-7410) to authorized networks only
2. Deploy DDS traffic inspection at network boundaries to detect malformed packets
3. Implement application-level monitoring with automatic restart capabilities for DDS processes
4. Disable DDS security mode if operationally feasible (reduces attack surface)

DETECTION RULES:
1. Monitor for SPDP packets with abnormally large vecsize values in DATA Submessages
2. Alert on Fast DDS process crashes with OOM (Out of Memory) errors
3. Track failed DDS authentication attempts from unexpected sources
4. Monitor for repeated connection attempts from single source IPs to DDS ports
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع الأنظمة التي تقوم بتشغيل إصدارات Fast DDS <3.4.1 أو <3.3.1 أو <2.6.11 باستخدام أدوات المسح والمخزون
2. تعطيل أو عزل الأنظمة مع تفعيل وضع الأمان حتى اكتمال التصحيح
3. تنفيذ تقسيم الشبكة لتقييد مصادر حزم SPDP للناشرين الموثوقين فقط
4. مراقبة إنهاء العمليات غير الطبيعية وأخطاء نفاد الذاكرة في تطبيقات DDS

إرشادات التصحيح:
1. ترقية Fast DDS إلى الإصدار 3.4.1 أو 3.3.1 أو 2.6.11 فوراً
2. اختبار التصحيحات في بيئات غير الإنتاج أولاً
3. تنسيق التصحيح مع مالكي الأنظمة لتقليل وقت التوقف
4. التحقق من تثبيت التصحيح بفحص أرقام الإصدارات بعد النشر

الضوابط البديلة (إذا تأخر التصحيح):
1. تنفيذ قواعد جدار الحماية لتقييد حركة SPDP متعددة الإرسال (منفذ UDP 7400-7410) للشبكات المصرح بها فقط
2. نشر فحص حركة DDS على حدود الشبكة للكشف عن الحزم المشوهة
3. تنفيذ مراقبة على مستوى التطبيق مع قدرات إعادة التشغيل التلقائي لعمليات DDS
4. تعطيل وضع أمان DDS إذا كان ممكناً من الناحية التشغيلية

قواعد الكشف:
1. مراقبة حزم SPDP بقيم vecsize كبيرة بشكل غير طبيعي في DATA Submessages
2. تنبيه عند توقف عملية Fast DDS مع أخطاء OOM
3. تتبع محاولات المصادقة الفاشلة في DDS من مصادر غير متوقعة
4. مراقبة محاولات الاتصال المتكررة من عناوين IP واحدة إلى منافذ DDS
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 — Management of technical vulnerabilities ECC 2024 A.14.2.1 — Secure development policy ECC 2024 A.12.2.1 — Change management procedures ECC 2024 A.12.1.2 — Monitoring and review of system access
🔵 SAMA CSF
SAMA CSF ID.RA-1 — Asset management and vulnerability identification SAMA CSF PR.IP-12 — Software development and acquisition security SAMA CSF DE.CM-1 — Detection and analysis of anomalies SAMA CSF RS.MI-2 — Incident response and recovery procedures
🟡 ISO 27001:2022
ISO 27001:2022 A.12.2.1 — Change management ISO 27001:2022 A.12.6.1 — Management of technical vulnerabilities ISO 27001:2022 A.14.2.1 — Secure development policy ISO 27001:2022 A.8.1.1 — Inventory of assets
🟣 PCI DSS v4.0.1
PCI DSS 6.2 — Security patches and updates PCI DSS 11.2 — Vulnerability scanning and assessment
📦 Affected Products / CPE 6 entries
eprosima:fast_dds
eprosima:fast_dds
eprosima:fast_dds:3.4.0
debian:debian_linux:11.0
debian:debian_linux:12.0
debian:debian_linux:13.0
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-122
EPSS0.02%
Exploit No
Patch ✓ Yes
Published 2026-02-03
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
patch-available CWE-122
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.