PT-2010-4441 · Wind River · Vxworks

Published

2010-08-04

·

Updated

2010-08-05

·

CVE-2010-2967

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Wind River VxWorks versions prior to 6.9
Description The issue is related to the loginDefaultEncrypt algorithm in loginLib, which does not properly support a large set of distinct possible passwords. This makes it easier for remote attackers to obtain access via a telnet, rlogin, or FTP session.
Recommendations For versions prior to 6.9, update to version 6.9 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2967

Affected Products

Vxworks