Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.
Wind River VxWorks versiones 6.6, 6.7, 6.8, 6.9.3, 6.9.4 y Vx7 tiene un control de acceso incorrecto en la asignación de IPv4 por el componente de cliente ipdhcpc DHCP.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
| Attack Vector | ADJACENT_NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | LOW |
| Availability Impact | HIGH |
AV:A/AC:L/Au:N/C:N/I:P/A:P
| Access Vector | ADJACENT_NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | NONE |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-88
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| windriver | vxworks | 6.6 | <built-in method update of dict object at 0x7e60baa09900> | Operating System |
| windriver | vxworks | 6.7 | <built-in method update of dict object at 0x7e6111c1fb00> | Operating System |
| windriver | vxworks | 6.8 | <built-in method update of dict object at 0x7e60baa0a700> | Operating System |
| windriver | vxworks | 6.9.3 | <built-in method update of dict object at 0x7e60e8875000> | Operating System |
| windriver | vxworks | 6.9.4 | <built-in method update of dict object at 0x7e60baa0bfc0> | Operating System |
| windriver | vxworks | 7.0 | <built-in method update of dict object at 0x7e60baa0a3c0> | Operating System |
| belden | hirschmann_hios | * | <built-in method update of dict object at 0x7e60e88772c0> | Operating System |
| belden | hirschmann_hios | * | <built-in method update of dict object at 0x7e60b8479540> | Operating System |
| belden | hirschmann_hios | * | <built-in method update of dict object at 0x7e6112e31980> | Operating System |
| belden | hirschmann_hios | * | <built-in method update of dict object at 0x7e60baa08280> | Operating System |
| belden | garrettcom_magnum_dx940e_firmware | * | <built-in method update of dict object at 0x7e61342e5f00> | Operating System |
| siemens | ruggedcom_win7000_firmware | * | <built-in method update of dict object at 0x7e60e8874c00> | Operating System |
| siemens | ruggedcom_win7018_firmware | * | <built-in method update of dict object at 0x7e6107469500> | Operating System |
| siemens | ruggedcom_win7025_firmware | * | <built-in method update of dict object at 0x7e611232c800> | Operating System |
| siemens | ruggedcom_win7200_firmware | * | <built-in method update of dict object at 0x7e60baa085c0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:windriver:vxworks:6.6:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:windriver:vxworks:6.7:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:windriver:vxworks:6.8:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:windriver:vxworks:6.9.3:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:windriver:vxworks:6.9.4:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:windriver:vxworks:7.0:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:hirschmann_ees20:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_ees25:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_eesx20:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_eesx30:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1020:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1030:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1042:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1120:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1130:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_grs1142:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_msp30:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_msp32:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rail_switch_power_lite:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rail_switch_power_smart:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_red25:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rsp20:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rsp25:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rsp30:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rsp35:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rspe30:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rspe32:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rspe35:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_rspe37:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:hirschmann_msp40:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_octopus_os3:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:hirschmann_dragon_mach4000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_dragon_mach4500:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:hirschmann_eagle_one:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_eagle20:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:belden:hirschmann_eagle30:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:garrettcom_magnum_dx940e_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:garrettcom_magnum_dx940e:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:ruggedcom_win7000_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:ruggedcom_win7000:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:ruggedcom_win7018_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:ruggedcom_win7018:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:ruggedcom_win7025_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:ruggedcom_win7025:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:ruggedcom_win7200_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:ruggedcom_win7200:-:*:*:*:*:*:*:* |