CVE-2025-67108 Details
Description
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
A vulnerability exists in eProsima Fast DDS version 3.3 due to improper validation of ticket revocation, leading to insecure communications and connections. The issue arises because the software only checks certificate expiration during the initial handshake, using OpenSSL's certificate verification. After the connection is established, continuous validation of certificate expiration is neglected. This flaw allows attackers to exploit short-term valid certificates to maintain connections and communications even after the certificates have expired, bypassing security policies and access controls. Consequently, this vulnerability undermines the certificate authentication mechanism of DDS Security, potentially causing compliance issues.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-298 | Improper Validation of Certificate Expiration | CISA-ADP |
| CWE-370 | Missing Check for Certificate Revocation after Initial Check | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| eprosima fast dds | 3.3.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 2, 2026 | Initial Analysis | [email protected] |
| Dec 23, 2025 | CVE Modified | CISA-ADP |
| Dec 23, 2025 | New CVE Received | [email protected] |