Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).
Wind River VxWorks versiones 6.6, 6.7, 6.8, 6.9 y 7, presenta un Control de Acceso Incorrecto en el componente cliente RARP. Vulnerabilidad de seguridad IPNET: Manejo de respuestas Reverse ARP no solicitadas (Fallo Lógico).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:L/Au:N/C:P/I:P/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| windriver | vxworks | 6.6 | <built-in method update of dict object at 0x72a9b0aad280> | Operating System |
| windriver | vxworks | 6.7 | <built-in method update of dict object at 0x72a9ccf8be80> | Operating System |
| windriver | vxworks | 6.8 | <built-in method update of dict object at 0x72a9b0aae300> | Operating System |
| windriver | vxworks | 6.9 | <built-in method update of dict object at 0x72a9b0928200> | Operating System |
| windriver | vxworks | 7.0 | <built-in method update of dict object at 0x72a9cd07b700> | Operating System |
| belden | hirschmann_hios | * | <built-in method update of dict object at 0x72a9cd078dc0> | Operating System |
| belden | hirschmann_hios | * | <built-in method update of dict object at 0x72a9b0928d00> | Operating System |
| belden | hirschmann_hios | * | <built-in method update of dict object at 0x72a9cd07bd40> | Operating System |
| belden | hirschmann_hios | * | <built-in method update of dict object at 0x72a9ccf88a00> | Operating System |
| belden | garrettcom_magnum_dx940e_firmware | * | <built-in method update of dict object at 0x72a9cd079640> | Operating System |
| siemens | ruggedcom_win7000_firmware | * | <built-in method update of dict object at 0x72a9b0c13080> | Operating System |
| siemens | ruggedcom_win7018_firmware | * | <built-in method update of dict object at 0x72a9b0aae880> | Operating System |
| siemens | ruggedcom_win7025_firmware | * | <built-in method update of dict object at 0x72a9cd07acc0> | Operating System |
| siemens | ruggedcom_win7200_firmware | * | <built-in method update of dict object at 0x72a9b092be80> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:windriver:vxworks:6.6:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:windriver:vxworks:6.7:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:windriver:vxworks:6.8:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:windriver:vxworks:6.9:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:windriver:vxworks:7.0:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:hirschmann_ees20:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_ees25:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_eesx20:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_eesx30:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1020:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1030:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1042:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1120:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1130:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1142:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_msp30:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_msp32:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rail_switch_power_lite:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rail_switch_power_smart:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_red25:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rsp20:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rsp25:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rsp30:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rsp35:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rspe30:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rspe32:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rspe35:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rspe37:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:hirschmann_msp40:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_octopus_os3:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:hirschmann_dragon_mach4000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_dragon_mach4500:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:hirschmann_eagle_one:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_eagle20:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_eagle30:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:garrettcom_magnum_dx940e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:garrettcom_magnum_dx940e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:ruggedcom_win7000_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:ruggedcom_win7000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:ruggedcom_win7018_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:ruggedcom_win7018:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:ruggedcom_win7025_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:ruggedcom_win7025:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:ruggedcom_win7200_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:ruggedcom_win7200:-:*:*:*:*:*:*:* |