CVE-2019-12264 is an Incorrect Access Control vulnerability in the IPv4 assignment of the ipdhcpc DHCP client component within Wind River VxWorks 6.6 through Vx7, affecting products from Belden, Siemens, and Wind River. With a CVSS score of 7.1 (HIGH), this vulnerability can be exploited with low attack complexity over an adjacent network, potentially leading to high availability impact. While there is no evidence of active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with four mentions and four media articles, including reports on critical systems and infusion pumps being affected.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.6CPE matchmatch criteria | cpe:2.3:o:windriver:vxworks:6.6:*:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:o:windriver:vxworks:6.7:*:*:*:*:*:*:* | ||
6.8CPE matchmatch criteria | cpe:2.3:o:windriver:vxworks:6.8:*:*:*:*:*:*:* | ||
6.9.3CPE matchmatch criteria | cpe:2.3:o:windriver:vxworks:6.9.3:*:*:*:*:*:*:* | ||
6.9.4CPE matchmatch criteria | cpe:2.3:o:windriver:vxworks:6.9.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019VxWorks security updates in Bosch Rexroth controllers
Aug 8, 2019