PT-2019-4737 · Wind River · Vxworks

Published

2019-08-09

·

Updated

2022-08-12

·

CVE-2019-12258

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wind River VxWorks versions 6.6 through 7
Description The issue is related to errors in forming TCP options in the TCP component, which can lead to a denial of service (DoS) of TCP connections via malformed TCP options. This can be exploited by a remote attacker to cause a service disruption.
Recommendations For versions 6.6 through 7, consider disabling the TCP component or restricting its use until a patch is available to prevent exploitation of the session fixation vulnerability.

Exploit

Fix

Race Condition

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01289
CVE-2019-12258

Affected Products

Vxworks