Back to Database
Status published
Critical
CVE-2019-12260
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow...
Vulnerability Description
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-12260
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://support2.windriver.com/index.php?page=security-notices
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009
- https://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdf
- https://security.netapp.com/advisory/ntap-20190802-0001/
- https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12260
- https://support.f5.com/csp/article/K41190253
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdf
- https://www.oracle.com//security-alerts/cpujul2021.html
More from windriver
View All →CVE-2022-38767
An issue was discovered in Wind River VxWorks 6.9 and...
Unknown
0
CVE-2022-23937
In Wind River VxWorks 6.9 and 7, a specific crafted...
Medium
5.3
CVE-2021-43268
An issue was discovered in VxWorks 6.9 through 7. In...
Medium
6.5
CVE-2021-29999
An issue was discovered in Wind River VxWorks through 6.8....
Critical
9.8
CVE-2021-29998
An issue was discovered in Wind River VxWorks before 6.5....
Critical
9.8
Affected Vendor
windriver
View all reports →Affected Software
vxworks, sonicos, siprotec 5 firmware, e-series santricity os controller, power meter 9410 firmware, power meter 9810 firmware, ruggedcom win7000 firmware, ruggedcom win7018 firmware, ruggedcom win7025 firmware, ruggedcom win7200 firmware, communications eagle, hirschmann hios, garrettcom magnum dx940e firmware
Vulnerable Versions:
6.5, 7.0, 5.9.0.0, 5.9.1.0., 6.2.0.0, 6.2.4.0, 6.2.5.0, 6.2.6.0, 6.2.7.0, 6.2.9.0, 6.5.0.0, 6.5.1.0, 6.5.2.0, 6.5.3.0, 6.5.4.0., 6.2.7.1, 6.2.7.7, 0, 8.00, 46.6.0
Timeline
Official Publish:
August 9th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.