Windriver
Windriver Vxworks: vulnerabilidades y CVE
Windriver Vxworks tiene 44 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE44
Últimos 12 meses5
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-104018 | Alta (8.8) | — | — | 1 oct 2026 | An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be… |
| CVE-2026-102006 | Media (5.5) | 0.10% | — | 28 sept 2026 | In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed… |
| CVE-2026-102005 | Media (5.5) | 0.10% | — | 28 sept 2026 | Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing… |
| CVE-2026-102004 | Alta (7.8) | 0.11% | — | 28 sept 2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09 |
| CVE-2026-97686 | Media (5.5) | 0.10% | — | 28 sept 2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling… |
| CVE-2024-28759 | Media (4.3) | 0.25% | — | 14 may 2024 | A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09. |
| CVE-2023-51787 | Alta (7.5) | 0.49% | — | 15 feb 2024 | An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory is not freed, resulting in a memory leak. |
| CVE-2023-38346 | Alta (8.8) | 1.5% | — | 22 sept 2023 | An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A… |
| CVE-2022-38767 | Alta (7.5) | 1.1% | — | 25 nov 2022 | An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure. |
| CVE-2022-23937 | Alta (7.5) | 1.0% | — | 29 mar 2022 | In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario. |
| CVE-2021-43268 | Media (6.5) | 0.88% | — | 24 nov 2021 | An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free. |
| CVE-2020-35198 | Crítica (9.8) | 2.5% | — | 12 may 2021 | An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller… |
| CVE-2021-29999 | Crítica (9.8) | 1.8% | — | 13 abr 2021 | An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server. |
| CVE-2021-29998 | Crítica (9.8) | 2.4% | — | 13 abr 2021 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. |
| CVE-2021-29997 | Media (5.3) | 1.0% | — | 13 abr 2021 | An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE. |
| CVE-2016-20009 | Crítica (9.8) | 1.9% | — | 11 mar 2021 | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer |
| CVE-2020-28895 | Alta (7.3) | 1.6% | — | 3 feb 2021 | In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by… |
| CVE-2020-11440 | Alta (7.5) | 1.1% | — | 23 jul 2020 | httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root. |
| CVE-2020-10664 | Alta (7.5) | 1.4% | — | 27 abr 2020 | The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference. |
| CVE-2019-12262 | Crítica (9.8) | 4.1% | — | 14 ago 2019 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw). |
| CVE-2019-12261 | Crítica (9.8) | 9.0% | — | 9 ago 2019 | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host. |
| CVE-2019-12260 | Crítica (9.8) | 23% | — | 9 ago 2019 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option. |
| CVE-2019-12258 | Alta (7.5) | 23% | — | 9 ago 2019 | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. |
| CVE-2019-12255 | Crítica (9.8) | 75% | — | 9 ago 2019 | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. |
| CVE-2019-12265 | Media (5.3) | 60% | — | 9 ago 2019 | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report. |
| CVE-2019-12263 | Alta (8.1) | 3.2% | — | 9 ago 2019 | Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition. |
| CVE-2019-12259 | Alta (7.5) | 16% | — | 9 ago 2019 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing. |
| CVE-2019-12257 | Alta (8.8) | 84% | — | 9 ago 2019 | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc. |
| CVE-2019-12256 | Crítica (9.8) | 27% | — | 9 ago 2019 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. |
| CVE-2019-12264 | Alta (7.1) | 8.3% | — | 5 ago 2019 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.