PT-2025-12456 · Wind River Systems · Vxworks 7

Published

2025-03-21

·

Updated

2025-03-22

·

CVE-2025-26500

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wind River Systems VxWorks 7 versions 22.06 through 24.03
Description The issue is related to Uncontrolled Resource Consumption, allowing Excessive Allocation in VxWorks 7. Specifically crafted USB packets may lead to the system becoming unavailable.
Recommendations For versions 22.06 through 24.03, consider restricting the handling of USB packets to prevent excessive allocation and potential system unavailability until a patch is available. As a temporary workaround, consider disabling the handling of specifically crafted USB packets to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26500

Affected Products

Vxworks 7