Vxworks
Vendor:
First CVE: Oct 3, 2008 · Active for 17 years
39
Total CVEs
More Total CVEs than 97% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vxworks over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2008
17 years ago
Most Recent CVE
Feb 15, 2024
890 days ago
CVE Severity & Scoring
Vxworks39 CVEs
21%
51%
28%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (66.7%)
Unknown11 (28.2%)
Physical0 (0.0%)
Adjacent Network2 (5.1%)
Attack Complexity
Low25 (64.1%)
High3 (7.7%)
Unknown11 (28.2%)
User Interaction
None28 (71.8%)
Unknown11 (28.2%)
Required0 (0.0%)
Privileges Required
Low1 (2.6%)
High0 (0.0%)
None27 (69.2%)
Unknown11 (28.2%)
Top CVEs
Signals from CVEs in this product scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12255CRITICAL Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. | Aug 9, 2019 | 9.8 | 81 | NO | YES |
CVE-2019-12257HIGH Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdh | Aug 9, 2019 | 8.8 | 74 | NO | NO |
CVE-2010-2965CRITICAL The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other produc | Aug 5, 2010 | 9.8 | 61 | NO | NO |
CVE-2019-12258HIGH Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. | Aug 9, 2019 | 7.5 | 48 | NO | YES |
CVE-2019-12265MEDIUM Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 | Aug 9, 2019 | 5.3 | 48 | NO | NO |
CVE-2019-12256CRITICAL Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. | Aug 9, 2019 | 9.8 | 45 | NO | NO |
CVE-2019-12260CRITICAL Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a ma | Aug 9, 2019 | 9.8 | 43 | NO | NO |
CVE-2019-12261CRITICAL Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion dur | Aug 9, 2019 | 9.8 | 35 | NO | NO |
CVE-2013-0714HIGH IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of service (daemon hang) via a crafted public-k | Mar 20, 2013 | 10.0 | 33 | NO | NO |
CVE-2019-12259HIGH Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP pa | Aug 9, 2019 | 7.5 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (39 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (39 CVEs).
Media Mentions
Signals from CVEs in this product scope (39 CVEs).
Top CNAs Publishing CVEs For Vxworks
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 13 | 7.8 | 10.8% | 0 | 1 |
| 7 | 1 | 7.5 | 0.5% | 0 | 0 |
| 6.9.4.12 | 3 | 8.1 | 1.5% | 0 | 0 |
| 6.9.4 | 1 | 7.1 | 8.3% | 0 | 0 |
| 6.9.3 | 1 | 7.1 | 8.3% | 0 | 0 |
| 6.9 | 10 | 7.5 | 3.1% | 0 | 0 |
| 6.8.3 | 1 | 7.5 | 1.3% | 0 | 0 |
| 6.8 | 10 | 7.3 | 3.9% | 0 | 0 |
| 6.7 | 10 | 7.3 | 3.9% | 0 | 0 |
| 6.6.4.1 | 1 | 5.8 | 3.7% | 0 | 0 |
| 6.6.4 | 1 | 5.8 | 3.7% | 0 | 0 |
| 6.6.3 | 1 | 5.8 | 3.7% | 0 | 0 |
| 6.6 | 9 | 7.3 | 3.7% | 0 | 0 |
| 6.5 | 6 | 6.7 | 3.1% | 0 | 0 |
| 6.4 | 4 | 7.9 | 2.7% | 0 | 0 |
| 6 | 3 | 7.8 | 1.6% | 0 | 0 |
| 5.5 | 5 | 8.2 | 3.6% | 0 | 0 |
| 5 | 4 | 8.2 | 3.0% | 0 | 0 |