IM
IronMonkey Threat Research

CVE-2010-2965 CRITICAL

Published: 2010-08-05 | Last Modified: 2026-06-16 | Status: Modified

Description

The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls, or manage tasks via requests to UDP port 17185, a related issue to CVE-2005-3804.

Additional Descriptions (1)

El servicio WDB target agent debug en Wind River VxWorks v6.x, v5.x, y anteriores, como los usados en el Rockwell Automation 1756-ENBT serie A con firmware v3.2.6 y v3.6.1 y otros productos, permiten a atacantes remotos leer o modificar a su elección direcciones de memoria, realizar llamdas a funciones, o administrar tareas a través de peticiones UDP al puerto 17185, relacionado con el comportamiento de CVE-2005-3804.

CVSS Metrics

Base Score: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Type: Secondary

Exploitability Score: 3.9

Impact Score: 5.9

Base Score: 10.0 (HIGH)

AV:N/AC:L/Au:N/C:C/I:C/A:C

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-863
134c704f-9b21-4f2e-91b3-4a467353bcc0 Secondary
en CWE-863

Affected Products

Vendor Product Version Update Type
rockwellautomation 1756-enbt\/a_firmware 3.2.6 <built-in method update of dict object at 0x7fd37019d900> Operating System
rockwellautomation 1756-enbt\/a_firmware 3.6.1 <built-in method update of dict object at 0x7fd3844622c0> Operating System
windriver vxworks * <built-in method update of dict object at 0x7fd368d25e40> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:rockwellautomation:1756-enbt\/a_firmware:3.2.6:*:*:*:*:*:*:*
Yes cpe:2.3:o:rockwellautomation:1756-enbt\/a_firmware:3.6.1:*:*:*:*:*:*:*
Yes cpe:2.3:o:windriver:vxworks:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:rockwellautomation:1756-enbt\/a:-:*:*:*:*:*:*:*

References