VendorsWind Rivervxworks6.9
Vulnerabilities

Wind River VxWorks 6.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2013-0714
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of service (daemon hang) via a crafted public-key authentication request.
Published 2013-03-20 · Modified
10.0EPSS 0.064
CVE-2019-12262
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).
Published 2019-08-14 · Modified
9.8EPSS 0.041
CVE-2015-7599
Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a username and password.
Published 2017-02-07 · Modified
9.3EPSS 0.059
CVE-2023-38346
An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior.
Published 2023-09-22 · Modified
8.8EPSS 0.015
CVE-2013-0711
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to cause a denial of service (daemon outage) via a crafted authentication request.
Published 2013-03-20 · Modified
7.8EPSS 0.033
CVE-2022-23937
In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario.
Published 2022-03-29 · Modified
7.5EPSS 0.010
CVE-2013-0712
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a crafted packet.
Published 2013-03-20 · Modified
6.8EPSS 0.026
CVE-2013-0713
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a crafted pty request.
Published 2013-03-20 · Modified
6.8EPSS 0.022
CVE-2013-0716
The web server in Wind River VxWorks 5.5 through 6.9 allows remote attackers to cause a denial of service (daemon crash) via a crafted URI.
Published 2013-03-20 · Modified
5.0EPSS 0.024
CVE-2013-0715
The WebCLI component in Wind River VxWorks 5.5 through 6.9 allows remote authenticated users to cause a denial of service (CLI session crash) via a crafted command string.
Published 2013-03-20 · Modified
4.0EPSS 0.019