CVE-2019-12261
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
Affected (33)
Products: Windriver: Vxworks · Sonicwall: Sonicos · Siemens: Siprotec 5 Firmware, Power Meter 9410 Firmware, Power Meter 9810 Firmware, Ruggedcom Win7000 Firmware, Ruggedcom Win7018 Firmware, Ruggedcom Win7025 Firmware, Ruggedcom Win7200 Firmware · +3 more
Show all products
Windriver: Vxworks · Sonicwall: Sonicos · Siemens: Siprotec 5 Firmware, Power Meter 9410 Firmware, Power Meter 9810 Firmware, Ruggedcom Win7000 Firmware, Ruggedcom Win7018 Firmware, Ruggedcom Win7025 Firmware, Ruggedcom Win7200 Firmware · Netapp: E Series Santricity Os Controller · Oracle: Communications Eagle · Belden: Hirschmann Hios, Garrettcom Magnum Dx940e Firmware
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.59 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.00 to 8.40.50.00 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.91 |
| Running on/with | Platform Versions |
|---|---|
Siemens Siprotec 5 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Power Meter 9410 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Power Meter 9810 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before bs5.2.461.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Win7000 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before bs5.2.461.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Win7018 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before bs5.2.461.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Win7025 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before bs5.2.461.17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Win7200 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 46.6.0 to 46.8.2 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 07.0.07 |
| Running on/with | Platform Versions |
|---|---|
Belden Hirschmann Ees20 | All versions |
Belden Hirschmann Ees25 | All versions |
Belden Hirschmann Eesx20 | All versions |
Belden Hirschmann Eesx30 | All versions |
Belden Hirschmann Grs1020 | All versions |
Belden Hirschmann Grs1030 | All versions |
Belden Hirschmann Grs1042 | All versions |
Belden Hirschmann Grs1120 | All versions |
Belden Hirschmann Grs1130 | All versions |
Belden Hirschmann Grs1142 | All versions |
Belden Hirschmann Msp30 | All versions |
Belden Hirschmann Msp32 | All versions |
Belden Hirschmann Rail Switch Power Lite | All versions |
Belden Hirschmann Rail Switch Power Smart | All versions |
Belden Hirschmann Red25 | All versions |
Belden Hirschmann Rsp20 | All versions |
Belden Hirschmann Rsp25 | All versions |
Belden Hirschmann Rsp30 | All versions |
Belden Hirschmann Rsp35 | All versions |
Belden Hirschmann Rspe30 | All versions |
Belden Hirschmann Rspe32 | All versions |
Belden Hirschmann Rspe35 | All versions |
Belden Hirschmann Rspe37 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 07.5.01 |
| Running on/with | Platform Versions |
|---|---|
Belden Hirschmann Msp40 | All versions |
Belden Hirschmann Octopus Os3 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 07.2.04 |
| Running on/with | Platform Versions |
|---|---|
Belden Hirschmann Dragon Mach4000 | All versions |
Belden Hirschmann Dragon Mach4500 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 05.3.06 |
| Running on/with | Platform Versions |
|---|---|
Belden Hirschmann Eagle20 | All versions |
Belden Hirschmann Eagle30 | All versions |
Belden Hirschmann Eagle One | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.0.1_y7 |
| Running on/with | Platform Versions |
|---|---|
Belden Garrettcom Magnum Dx940e | All versions |
References (20)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Issue TrackingVendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.