Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wind River Systems Inc.

First CVE: Aug 1, 1997Active for: 29 yearsTotal CVEs: 48
60.1
VTI Score
TOP TARGET

Wind River Systems maintains a narrow but strategically important portfolio of embedded real-time operating systems and platform software, with VxWorks, a foundational real-time OS deployed across industrial control, aerospace, and critical infrastructure environments, representing the dominant exposure vector. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency to acquire public exploit code, reflecting the memory-safety challenges inherent to large C-based kernel codebases and the high-value nature of compromising embedded control systems. The recurring weakness classes—improper input validation, classic buffer overflows, out-of-bounds writes, and integer overflows—are characteristic of low-level systems programming and concentrate in protocol parsers, device drivers, and network-facing components that frequently operate with elevated privilege in production deployments. Defenders should track this vendor's advisories closely and prioritize patching for internet-accessible or network-adjacent instances, particularly in operational technology and critical infrastructure contexts where remediation cycles may be constrained. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
48
Total CVEs
More Total CVEs than 98% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wind River Systems Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 1997
28 years ago
Most Recent CVE
Feb 15, 2024
890 days ago

Self-Reporting Analysis

Of all the CVEs published by Wind River Systems Inc. as a CNA, 0.0% affect products that Wind River Systems Inc. develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 3 (100.0%)

Of all the CVEs published that affect products developed by Wind River Systems Inc., 0.0% are self-published by Wind River Systems Inc. as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 48 (100.0%)

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12255CRITICAL
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
Aug 9, 20199.881NOYES
CVE-2002-1337HIGH
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a
Mar 7, 200310.080NOYES
CVE-2019-12257HIGH
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdh
Aug 9, 20198.874NONO
CVE-2010-2965CRITICAL
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other produc
Aug 5, 20109.861NONO
CVE-2019-12258HIGH
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
Aug 9, 20197.548NOYES
CVE-2019-12265MEDIUM
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3
Aug 9, 20195.348NONO
CVE-2019-12256CRITICAL
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
Aug 9, 20199.845NONO
CVE-2019-12260CRITICAL
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a ma
Aug 9, 20199.843NONO
CVE-2007-4938HIGH
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbi
Sep 18, 20077.636NOYES
CVE-2007-2736HIGH
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.
May 17, 200710.036NOYES
View all 48 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products48 CVEs
23%
54%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.1%)
Network27 (56.3%)
Unknown18 (37.5%)
Physical0 (0.0%)
Adjacent Network2 (4.2%)
Attack Complexity
Low26 (54.2%)
High4 (8.3%)
Unknown18 (37.5%)
User Interaction
None30 (62.5%)
Unknown18 (37.5%)
Required0 (0.0%)
Privileges Required
Low1 (2.1%)
High0 (0.0%)
None29 (60.4%)
Unknown18 (37.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
14.6% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wind River Systems Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wind River Systems Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wind River Systems Inc.'s Products

View all 6 CNAs →

Top CWEs