CRITICAL
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component
Published Aug 14, 2019
9.8
CRITICALCVSS 3.1
EPSS 4.12%
Description
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).
Affected products
No data.
Configuration 1
Configuration 2
AND
- ≤ 07.0.07
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 3
AND
- ≤ 07.5.01
Running on/with
OR
- n/a
- n/a
Configuration 4
AND
- ≤ 07.2.04
Running on/with
OR
- n/a
- n/a
Configuration 5
AND
- ≤ 05.3.06
Running on/with
OR
- n/a
- n/a
- n/a
Configuration 6
AND
- ≤ 1.0.1_y7
Running on/with
- n/a
Configuration 7
AND
- < bs5.2.461.17
Running on/with
- n/a
Configuration 8
AND
- < bs5.2.461.17
Running on/with
- n/a
Configuration 9
AND
- < bs5.2.461.17
Running on/with
- n/a
Configuration 10
AND
- < bs5.2.461.17
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (4)
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdf x_refsource_CONFIRMThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdf x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K41190253 x_refsource_CONFIRMThird Party Advisory
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12262 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdf | x_refsource_CONFIRMThird Party Advisory | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdf | x_refsource_CONFIRMThird Party Advisory | |
| https://support.f5.com/csp/article/K41190253 | x_refsource_CONFIRMThird Party Advisory | |
| https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12262 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 14, 2019
Updated Aug 4, 2024
Reserved May 21, 2019
Link CVE-2019-12262
CISA Vulnrichment
Updated n/a