← Back

CVE-2010-2966

nvd nist
Published: Aug 5, 2010Modified: Apr 29, 2026

JSON object

Loading...
7.8
Vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
Exploitability: 10.0 / Impact: 6.9
Source: NVD

Description

The INCLUDE_SECURITY functionality in Wind River VxWorks 6.x, 5.x, and earlier uses the LOGIN_USER_NAME and LOGIN_USER_PASSWORD (aka LOGIN_PASSWORD) parameters to create hardcoded credentials, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session.

Affected (5)

Products: Windriver: Vxworks
1 product
Vxworks
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Windriver
Up to 6.8
Version 5.5
Version 5
Version 6.4
Version 6

Related CWEs

References (4)

Source: cve@mitre.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource

Timeline

No history available yet.