IM
IronMonkey Threat Research

CVE-2019-12264 HIGH

Published: 2019-08-05 | Last Modified: 2026-06-17 | Status: Modified

Description

Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

Additional Descriptions (1)

Wind River VxWorks versiones 6.6, 6.7, 6.8, 6.9.3, 6.9.4 y Vx7 tiene un control de acceso incorrecto en la asignación de IPv4 por el componente de cliente ipdhcpc DHCP.

CVSS Metrics

Base Score: 7.1 (HIGH)

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack VectorADJACENT_NETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactLOW
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 4.2

Base Score: 4.8 (MEDIUM)

AV:A/AC:L/Au:N/C:N/I:P/A:P

Access VectorADJACENT_NETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 6.5

Impact Score: 4.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-88

Affected Products

Vendor Product Version Update Type
windriver vxworks 6.6 <built-in method update of dict object at 0x7e60baa09900> Operating System
windriver vxworks 6.7 <built-in method update of dict object at 0x7e6111c1fb00> Operating System
windriver vxworks 6.8 <built-in method update of dict object at 0x7e60baa0a700> Operating System
windriver vxworks 6.9.3 <built-in method update of dict object at 0x7e60e8875000> Operating System
windriver vxworks 6.9.4 <built-in method update of dict object at 0x7e60baa0bfc0> Operating System
windriver vxworks 7.0 <built-in method update of dict object at 0x7e60baa0a3c0> Operating System
belden hirschmann_hios * <built-in method update of dict object at 0x7e60e88772c0> Operating System
belden hirschmann_hios * <built-in method update of dict object at 0x7e60b8479540> Operating System
belden hirschmann_hios * <built-in method update of dict object at 0x7e6112e31980> Operating System
belden hirschmann_hios * <built-in method update of dict object at 0x7e60baa08280> Operating System
belden garrettcom_magnum_dx940e_firmware * <built-in method update of dict object at 0x7e61342e5f00> Operating System
siemens ruggedcom_win7000_firmware * <built-in method update of dict object at 0x7e60e8874c00> Operating System
siemens ruggedcom_win7018_firmware * <built-in method update of dict object at 0x7e6107469500> Operating System
siemens ruggedcom_win7025_firmware * <built-in method update of dict object at 0x7e611232c800> Operating System
siemens ruggedcom_win7200_firmware * <built-in method update of dict object at 0x7e60baa085c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:windriver:vxworks:6.6:*:*:*:*:*:*:*
Yes cpe:2.3:o:windriver:vxworks:6.7:*:*:*:*:*:*:*
Yes cpe:2.3:o:windriver:vxworks:6.8:*:*:*:*:*:*:*
Yes cpe:2.3:o:windriver:vxworks:6.9.3:*:*:*:*:*:*:*
Yes cpe:2.3:o:windriver:vxworks:6.9.4:*:*:*:*:*:*:*
Yes cpe:2.3:o:windriver:vxworks:7.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:belden:hirschmann_ees20:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_ees25:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_eesx20:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_eesx30:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_grs1020:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_grs1030:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_grs1042:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_grs1120:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_grs1130:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_grs1142:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_msp30:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_msp32:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rail_switch_power_lite:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rail_switch_power_smart:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_red25:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rsp20:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rsp25:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rsp30:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rsp35:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rspe30:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rspe32:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rspe35:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_rspe37:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:belden:hirschmann_msp40:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_octopus_os3:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:belden:hirschmann_dragon_mach4000:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_dragon_mach4500:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:belden:hirschmann_eagle_one:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_eagle20:-:*:*:*:*:*:*:*
No cpe:2.3:h:belden:hirschmann_eagle30:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:belden:garrettcom_magnum_dx940e_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:belden:garrettcom_magnum_dx940e:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:ruggedcom_win7000_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:ruggedcom_win7000:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:ruggedcom_win7018_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:ruggedcom_win7018:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:ruggedcom_win7025_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:ruggedcom_win7025:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:ruggedcom_win7200_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:ruggedcom_win7200:-:*:*:*:*:*:*:*
Notification
Message here