PT-2013-2552 · Wind River · Vxworks

Hisashi Kojima

+1

·

Published

2013-03-20

·

Updated

2013-05-21

·

CVE-2013-0714

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Wind River VxWorks versions 6.5 through 6.9
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service, resulting in a daemon hang, via a crafted public-key authentication request in the IPSSH server.
Recommendations For versions 6.5 through 6.9, consider disabling public-key authentication as a temporary workaround until a patch is available. Restrict access to the IPSSH server to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0714

Affected Products

Vxworks