eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used to disconnect between nodes are not encrypted, a vulnerability has been discovered where a malicious attacker can forcibly disconnect a Subscriber and can deny a Subscriber attempting to connect. Afterwards, if the attacker sends the packet for disconnecting, which is data (`p[UD]`), to the Global Data Space (`239.255.0.1:7400`) using the said Publisher ID, all the Subscribers (Listeners) connected to the Publisher (Talker) will not receive any data and their connection will be disconnected. Moreover, if this disconnection packet is sent continuously, the Subscribers (Listeners) trying to connect will not be able to do so. Since the initial commit of the `SecurityManager.cpp` code (`init`, `on_process_handshake`) on Nov 8, 2016, the Disconnect Vulnerability in RTPS Packets Used by SROS2 has been present prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7.
Conclusion & alert: CVE-2023-50257 is rated Moderate Risk (53.2/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.20%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-03 | 0.07% | 0.20% | +0.13% |
| 2 | 2025-11-21 | 0.15% | 0.07% | -0.08% |
| 3 | 2025-11-18 | — | 0.15% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.6 | 3.1 | CRITICAL |
|
2.8 | 6.0 | [email protected] |
| 8.1 | 3.1 | HIGH |
|
2.8 | 5.2 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2023-50257 not yet assigned priority: Debian including 1 source packages (fastdds), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 3, open 2. | https://security-tracker.debian.org/tracker/CVE-2023-50257 |
ubuntu
|
medium | CVE-2023-50257 medium priority: Ubuntu including 1 source packages (fastdds), 7 status rows across 7 suites (focal, jammy, noble, oracular, plucky, questing, upstream): not-affected 3, needs-triage 2, DNE 1, released 1. | https://ubuntu.com/security/CVE-2023-50257 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| eprosima | fast_dds | < 2.6.7 | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* |
| eprosima | fast_dds | >= 2.10.0, < 2.10.3 | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* |
| eprosima | fast_dds | >= 2.11.0, < 2.11.3 | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* |
| eprosima | fast_dds | >= 2.12.0, < 2.12.2 | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* |