CRITICAL🇵🇱 Wersja polska

CVE-2024-52057

CVSS 9.1v4.0pub. 2024-12-13upd. 2025-10-02

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Professional (Queuing Service) allows SQL Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0, from 6.1.0 before 6.1.2.17, from 6.0.0 before 6.0.*, from 5.2.0 before 5.3.*.

🤖 AI Analysis
How it works

The vulnerability results from improper neutralization of special characters in SQL queries in the Queuing Service component. A remote unauthenticated attacker can inject malicious SQL commands into queries directed to the database. This requires certain technical conditions to be met on the environment side (AT:P in the CVSS vector), but does not require any user interaction.

Impact

A successful attack allows unauthorized reading and modification of data stored in the RTI Connext Professional system database. This can lead to disclosure of sensitive information and compromise of data integrity processed by the system.

Mitigation & patch

RTI Connext Professional should be updated to version 7.3.0 or newer (for the 7.x branch) or to version 6.1.2.17 or newer (for the 6.1.x branch). Users of the 6.0.x and 5.2.x branches should consult with the vendor and apply patches available according to references at https://www.rti.com/vulnerabilities/#cve-2024-52057. It is recommended to limit network access to the Queuing Service only to trusted hosts as a temporary measure.

Who is affected

RTI Connext Professional in versions: from 7.0.0 before 7.3.0, from 6.1.0 before 6.1.2.17, from 6.0.0 before 6.0.* (all versions of the 6.0.x branch), from 5.2.0 before 5.3.* (all versions of the 5.2.x branch).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Rti Connext Professional

    APP
    Rti
    5.2.0 – 6.1.2.17 (excl.)7.0.0 – 7.3.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-3894CRITICAL9.2PL ✓same product

Out-of-bounds Read w RTI Connext Professional — przeciążenie dostępności

CVE-2026-2467CRITICAL9.2PL ✓same product

Heap-based Buffer Overflow w RTI Connext Professional (Core Libraries)

CVE-2026-7300HIGH8.8same product

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Profession...

CVE-2025-14543HIGH8.8same product

Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) a...

CVE-2026-4374HIGH8.8same product

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Routing Servi...