Summary
Detail | |||
---|---|---|---|
Vendor | Windriver | First view | 2008-10-03 |
Product | Vxworks | Last view | 2023-09-22 |
Version | Type | Os | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
Related : CVE
Date | Alert | Description | |
---|---|---|---|
8.8 | 2023-09-22 | CVE-2023-38346 | An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior. |
7.5 | 2022-11-25 | CVE-2022-38767 | An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure. |
7.5 | 2022-03-29 | CVE-2022-23937 | In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario. |
6.5 | 2021-11-24 | CVE-2021-43268 | An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free. |
9.8 | 2021-05-12 | CVE-2020-35198 | An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption. |
9.8 | 2021-04-13 | CVE-2021-29999 | An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server. |
9.8 | 2021-04-13 | CVE-2021-29998 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. |
5.3 | 2021-04-13 | CVE-2021-29997 | An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE. |
9.8 | 2021-03-11 | CVE-2016-20009 | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer |
7.3 | 2021-02-03 | CVE-2020-28895 | In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption. |
7.5 | 2020-07-23 | CVE-2020-11440 | httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root. |
7.5 | 2020-04-27 | CVE-2020-10664 | The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference. |
9.8 | 2019-08-14 | CVE-2019-12262 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw). |
5.3 | 2019-08-09 | CVE-2019-12265 | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report. |
8.1 | 2019-08-09 | CVE-2019-12263 | Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition. |
9.8 | 2019-08-09 | CVE-2019-12261 | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host. |
9.8 | 2019-08-09 | CVE-2019-12260 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option. |
7.5 | 2019-08-09 | CVE-2019-12259 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing. |
7.5 | 2019-08-09 | CVE-2019-12258 | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. |
8.8 | 2019-08-09 | CVE-2019-12257 | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc. |
9.8 | 2019-08-09 | CVE-2019-12256 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. |
9.8 | 2019-08-09 | CVE-2019-12255 | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. |
7.1 | 2019-08-05 | CVE-2019-12264 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component. |
8.1 | 2019-05-29 | CVE-2019-9865 | When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer overflow leading to an out-of-bounds memory copy. It may allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code. |
8.1 | 2017-02-07 | CVE-2015-7599 | Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a username and password. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
20% (7) | CWE-20 | Improper Input Validation |
14% (5) | CWE-787 | Out-of-bounds Write |
14% (5) | CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflo... |
11% (4) | CWE-190 | Integer Overflow or Wraparound |
5% (2) | CWE-476 | NULL Pointer Dereference |
5% (2) | CWE-125 | Out-of-bounds Read |
2% (1) | CWE-415 | Double Free |
2% (1) | CWE-401 | Failure to Release Memory Before Removing Last Reference ('Memory L... |
2% (1) | CWE-384 | Session Fixation |
2% (1) | CWE-362 | Race Condition |
2% (1) | CWE-330 | Use of Insufficiently Random Values |
2% (1) | CWE-310 | Cryptographic Issues |
2% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
2% (1) | CWE-255 | Credentials Management |
2% (1) | CWE-88 | Argument Injection or Modification |
2% (1) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |
Oval Markup Language : Definitions
OvalID | Name |
---|---|
oval:org.mitre.oval:def:5670 | HP-UX Running IPv6, Remote Denial of Service (DoS) and Unauthorized Access |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
66910 | Wind River Systems' VxWorks FTP Daemon TCP Connection Termination Weakness |
66909 | Wind River Systems' VxWorks INCLUDE_SECURITY Functionality Multiple Parameter... |
66843 | Wind River Systems' VxWorks loginLib Default Hashing Algorithm Weakness |
66842 | Wind River Systems' VxWorks WDB Debug Service Remote Arbitrary Memory Manipul... |
52494 | Apple Multiple Products IPv6 Neighbor Discovery Protocol Neighbor Solicitatio... |
49407 | NetBSD IPv6 Neighbor Discovery Protocol Neighbor Solicitation Spoofing |
48989 | Juniper Multiple Products IPv6 Neighbor Discovery Protocol Neighbor Solicitat... |
48745 | Force10 FTOS Routers IPv6 Neighbor Discovery Protocol Neighbor Solicitation S... |
48744 | OpenBSD IPv6 Neighbor Discovery Protocol Neighbor Solicitation Spoofing |
48702 | FreeBSD IPv6 Neighbor Discovery Protocol Neighbor Solicitation Spoofing |
OpenVAS Exploits
id | Description |
---|---|
2011-12-14 | Name : VxWorks Debugging Service Security-Bypass Vulnerability File : nvt/gb_xvworks_debugging_service_42158.nasl |
2009-05-05 | Name : HP-UX Update for IPv6 HPSBUX02407 File : nvt/gb_hp_ux_HPSBUX02407.nasl |
2008-10-03 | Name : FreeBSD Security Advisory (FreeBSD-SA-08:10.nd6.asc) File : nvt/freebsdsa_nd6.nasl |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2015-B-0082 | Wind River VxWorks TCP Predictability Vulnerability Severity: Category I - VMSKEY: V0060987 |
2013-B-0054 | Multiple Vulnerabilities in Wind River VxWorks Severity: Category I - VMSKEY: V0037949 |
2008-B-0070 | Multiple Vendors IPv6 Neighbor Discovery Protocol Spoofing Vulnerability Severity: Category II - VMSKEY: V0017557 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Multiple Operating Systems invalid DHCP option attempt RuleID : 7196 - Type : OS-OTHER - Revision : 13 |
2020-12-08 | VxWorks TCP URG memory corruption attempt RuleID : 51111 - Type : OS-OTHER - Revision : 1 |
2019-09-17 | DHCP broadcast address offer attempt RuleID : 51069 - Type : POLICY-OTHER - Revision : 1 |
2019-09-17 | DHCP multicast address offer attempt RuleID : 51068 - Type : POLICY-OTHER - Revision : 1 |
2019-09-17 | DHCP loopback address offer attempt RuleID : 51067 - Type : POLICY-OTHER - Revision : 1 |
2019-09-17 | TCP SYN packet and URG set attempt RuleID : 51066 - Type : POLICY-OTHER - Revision : 1 |
2019-09-17 | TCP FIN packet and URG set attempt RuleID : 51065 - Type : POLICY-OTHER - Revision : 1 |
2019-09-17 | IGMP membership query attempt RuleID : 51037 - Type : POLICY-OTHER - Revision : 1 |
2019-09-17 | IP option loose source routing attempt RuleID : 51036 - Type : POLICY-OTHER - Revision : 1 |
2019-09-17 | IP option strict source routing attempt RuleID : 51035 - Type : POLICY-OTHER - Revision : 1 |
2019-09-17 | IP option loose source routing attempt RuleID : 51034 - Type : POLICY-OTHER - Revision : 1 |
2018-01-04 | vxworks rpc credential flavor integer overflow device crash attempt RuleID : 45101 - Type : PROTOCOL-SCADA - Revision : 2 |
2014-01-10 | VxWorks remote debugging agent login attempt RuleID : 17110 - Type : APP-DETECT - Revision : 5 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2016-01-28 | Name: The remote device is missing a vendor-supplied security patch. File: f5_bigip_SOL9528.nasl - Type: ACT_GATHER_INFO |
2015-12-11 | Name: The remote multi-function device is affected by multiple vulnerabilities. File: xerox_xrx15av.nasl - Type: ACT_GATHER_INFO |
2015-06-25 | Name: The remote VxWorks device is potentially affected by a TCP predictability vul... File: vxworks_cve-2015-3963.nasl - Type: ACT_GATHER_INFO |
2013-09-13 | Name: The remote VxWorks device is potentially affected by several vulnerabilities. File: vxworks_ipssh_and_www_multi_dos.nasl - Type: ACT_GATHER_INFO |
2010-08-06 | Name: Arbitrary commands can be run on this port. File: wdb_agent_detect.nasl - Type: ACT_GATHER_INFO |
2009-02-12 | Name: The remote HP-UX host is missing a security-related patch. File: hpux_PHNE_37897.nasl - Type: ACT_GATHER_INFO |
2009-02-12 | Name: The remote HP-UX host is missing a security-related patch. File: hpux_PHNE_37898.nasl - Type: ACT_GATHER_INFO |
2009-02-12 | Name: The remote HP-UX host is missing a security-related patch. File: hpux_PHNE_38680.nasl - Type: ACT_GATHER_INFO |