Back to Database
Status published
High
CVE-2024-52058
Potential arbitrary command execution in System Designer while parsing malicious HTTP/REST requests
Vulnerability Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext Professional (System Designer) allows OS Command Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.0 before 6.1.2.19.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-52058
Credits & Attribution
No credits recorded in the NVD database.
More from RTI
View All →CVE-2025-8410
Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.
Medium
5.8
CVE-2025-4993
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.
High
8.3
CVE-2025-4582
Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers.
Medium
4.8
CVE-2025-1255
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.
High
8.3
CVE-2025-1254
Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers.
High
7.3
Affected Vendor
Affected Software
Connext Professional
Vulnerable Versions:
7.0.0, 6.1.0
Timeline
Official Publish:
December 13th, 2024
Last Modified:
February 7th, 2025
Added to House:
July 22nd, 2026