Vxworks

Vendor:

First CVE: Oct 3, 2008 · Active for 17 years

39
Total CVEs
More Total CVEs than 97% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Vxworks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2008
17 years ago
Most Recent CVE
Feb 15, 2024
890 days ago

CVE Severity & Scoring

Vxworks39 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (66.7%)
Unknown11 (28.2%)
Physical0 (0.0%)
Adjacent Network2 (5.1%)
Attack Complexity
Low25 (64.1%)
High3 (7.7%)
Unknown11 (28.2%)
User Interaction
None28 (71.8%)
Unknown11 (28.2%)
Required0 (0.0%)
Privileges Required
Low1 (2.6%)
High0 (0.0%)
None27 (69.2%)
Unknown11 (28.2%)

Top CVEs

Signals from CVEs in this product scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
Aug 9, 20199.881NOYES
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdh
Aug 9, 20198.874NONO
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other produc
Aug 5, 20109.861NONO
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
Aug 9, 20197.548NOYES
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3
Aug 9, 20195.348NONO
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
Aug 9, 20199.845NONO
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a ma
Aug 9, 20199.843NONO
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion dur
Aug 9, 20199.835NONO
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of service (daemon hang) via a crafted public-k
Mar 20, 201310.033NONO
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP pa
Aug 9, 20197.532NONO

Exploit Exposure

Signals from CVEs in this product scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (39 CVEs).

Media Mentions

Signals from CVEs in this product scope (39 CVEs).

Top CNAs Publishing CVEs For Vxworks

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0137.810.8%01
717.50.5%00
6.9.4.1238.11.5%00
6.9.417.18.3%00
6.9.317.18.3%00
6.9107.53.1%00
6.8.317.51.3%00
6.8107.33.9%00
6.7107.33.9%00
6.6.4.115.83.7%00
6.6.415.83.7%00
6.6.315.83.7%00
6.697.33.7%00
6.566.73.1%00
6.447.92.7%00
637.81.6%00
5.558.23.6%00
548.23.0%00