{"id":"CVE-2019-15136","details":"The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partition.","modified":"2026-07-08T20:05:17.887168Z","published":"2019-08-18T16:15:10.567Z","references":[{"type":"ADVISORY","url":"https://arxiv.org/abs/1908.05310"},{"type":"FIX","url":"https://github.com/eProsima/Fast-RTPS/issues/443"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eprosima/fast-dds","events":[{"introduced":"0"},{"last_affected":"b0c375ed46d08f98898e8dc641645076977e83cc"}],"database_specific":{"cpe":"cpe:2.3:a:eprosima:fast-rtps:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.9.0"}],"source":"CPE_RANGE"}}],"versions":["v1.7.2","v1.9.0","v1.9.0-beta-2","v1.9.0-beta","v1.8.0-2","v1.8.0","v1.7.1","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15136.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}