PT-2021-23790 · Vxworks · Vxworks

Published

2021-11-24

·

Updated

2021-12-01

·

CVE-2021-43268

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions VxWorks versions 6.9 through 7
Description An issue in the IKE component allows a specifically crafted packet to potentially lead to reading beyond the end of a buffer or a double free.
Recommendations For VxWorks versions 6.9 through 7, consider applying configuration changes to restrict the handling of crafted packets in the IKE component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43268

Affected Products

Vxworks