Windriver
Windriver Vxworks: vulnerabilities and CVEs
Windriver Vxworks has 44 published vulnerabilities, 5 of them in the last 12 months. 10 are rated critical and 0 are listed by CISA as actively exploited.
CVEs44
Last 12 months5
Critical10
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-104018 | High (8.8) | — | — | Oct 1, 2026 | An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be… |
| CVE-2026-102006 | Medium (5.5) | 0.10% | — | Sep 28, 2026 | In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed… |
| CVE-2026-102005 | Medium (5.5) | 0.10% | — | Sep 28, 2026 | Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing… |
| CVE-2026-102004 | High (7.8) | 0.11% | — | Sep 28, 2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09 |
| CVE-2026-97686 | Medium (5.5) | 0.10% | — | Sep 28, 2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling… |
| CVE-2024-28759 | Medium (4.3) | 0.25% | — | May 14, 2024 | A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09. |
| CVE-2023-51787 | High (7.5) | 0.49% | — | Feb 15, 2024 | An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory is not freed, resulting in a memory leak. |
| CVE-2023-38346 | High (8.8) | 1.5% | — | Sep 22, 2023 | An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A… |
| CVE-2022-38767 | High (7.5) | 1.1% | — | Nov 25, 2022 | An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure. |
| CVE-2022-23937 | High (7.5) | 1.0% | — | Mar 29, 2022 | In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario. |
| CVE-2021-43268 | Medium (6.5) | 0.88% | — | Nov 24, 2021 | An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free. |
| CVE-2020-35198 | Critical (9.8) | 2.5% | — | May 12, 2021 | An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller… |
| CVE-2021-29999 | Critical (9.8) | 1.8% | — | Apr 13, 2021 | An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server. |
| CVE-2021-29998 | Critical (9.8) | 2.4% | — | Apr 13, 2021 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. |
| CVE-2021-29997 | Medium (5.3) | 1.0% | — | Apr 13, 2021 | An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE. |
| CVE-2016-20009 | Critical (9.8) | 1.9% | — | Mar 11, 2021 | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer |
| CVE-2020-28895 | High (7.3) | 1.6% | — | Feb 3, 2021 | In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by… |
| CVE-2020-11440 | High (7.5) | 1.1% | — | Jul 23, 2020 | httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root. |
| CVE-2020-10664 | High (7.5) | 1.4% | — | Apr 27, 2020 | The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference. |
| CVE-2019-12262 | Critical (9.8) | 4.1% | — | Aug 14, 2019 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw). |
| CVE-2019-12261 | Critical (9.8) | 9.0% | — | Aug 9, 2019 | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host. |
| CVE-2019-12260 | Critical (9.8) | 23% | — | Aug 9, 2019 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option. |
| CVE-2019-12258 | High (7.5) | 23% | — | Aug 9, 2019 | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. |
| CVE-2019-12255 | Critical (9.8) | 75% | — | Aug 9, 2019 | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. |
| CVE-2019-12265 | Medium (5.3) | 60% | — | Aug 9, 2019 | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report. |
| CVE-2019-12263 | High (8.1) | 3.2% | — | Aug 9, 2019 | Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition. |
| CVE-2019-12259 | High (7.5) | 16% | — | Aug 9, 2019 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing. |
| CVE-2019-12257 | High (8.8) | 84% | — | Aug 9, 2019 | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc. |
| CVE-2019-12256 | Critical (9.8) | 27% | — | Aug 9, 2019 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. |
| CVE-2019-12264 | High (7.1) | 8.3% | — | Aug 5, 2019 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.