PT-2019-4737 · Wind River · Vxworks

Publicado

2019-08-09

·

Atualizado

2022-08-12

·

CVE-2019-12258

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wind River VxWorks versions 6.6 through 7
Description The issue is related to errors in forming TCP options in the TCP component, which can lead to a denial of service (DoS) of TCP connections via malformed TCP options. This can be exploited by a remote attacker to cause a service disruption.
Recommendations For versions 6.6 through 7, consider disabling the TCP component or restricting its use until a patch is available to prevent exploitation of the session fixation vulnerability.

Exploit

Correção

Race Condition

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-01289
CVE-2019-12258

Produtos afetados

Vxworks