CVE-2019-12260 is a critical buffer overflow vulnerability in the TCP component of Wind River VxWorks 6.9 and vx7, specifically related to a malformed TCP AO option causing state confusion. This vulnerability impacts a wide range of products from vendors like Belden, NetApp, Oracle, Siemens, SonicWall, and Wind River. With a CVSS score of 9.8 (CRITICAL), it allows unauthenticated attackers to achieve high confidentiality, integrity, and availability impacts over the network with low attack complexity. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness despite not being listed in the KEV catalog or Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.5, < 6.9.4.12CPE matchmatch criteria | cpe:2.3:o:windriver:vxworks:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:windriver:vxworks:7.0:-:*:*:*:*:*:* | ||
>= 5.9.0.0, <= 5.9.0.7CPE matchmatch criteria | cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:* | ||
>= 5.9.1.0., <= 5.9.1.12CPE matchmatch criteria | cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:* | ||
>= 6.2.0.0, <= 6.2.3.1CPE matchmatch criteria | cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019