PT-2013-2552 · Wind River · Vxworks
Hisashi Kojima
+1
·
Published
2013-03-20
·
Updated
2013-05-21
·
CVE-2013-0714
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wind River VxWorks versions 6.5 through 6.9
Description
The issue allows remote attackers to execute arbitrary code or cause a denial of service, resulting in a daemon hang, via a crafted public-key authentication request in the IPSSH server.
Recommendations
For versions 6.5 through 6.9, consider disabling public-key authentication as a temporary workaround until a patch is available. Restrict access to the IPSSH server to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vxworks