Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Moderate
CVE-2019-12256 - VxWorks IPv4 Options Buffer Overflow
Disclosure Date: August 09, 2019 (last updated December 06, 2023)
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
0
Attacker Value
Unknown
CVE-2021-27734
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.
0
Attacker Value
Unknown
CVE-2020-9307
Disclosure Date: February 11, 2021 (last updated February 22, 2025)
Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An unauthenticated, adjacent attacker can cause an infinite loop on one of the HSR ring ports of the device. This effectively breaks the redundancy of the HSR ring. If the attacker can perform the same attack on a second device, the ring is broken into two parts (thus disrupting communication between devices in the different parts).
0
Attacker Value
Unknown
CVE-2020-6994
Disclosure Date: April 03, 2020 (last updated February 21, 2025)
A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.
0
Attacker Value
Unknown
CVE-2019-12262
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).
0
Attacker Value
Unknown
CVE-2019-12260
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.
0
Attacker Value
Unknown
CVE-2019-12261
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
0
Attacker Value
Unknown
CVE-2019-12258
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
0
Attacker Value
Unknown
CVE-2019-12255
Disclosure Date: August 09, 2019 (last updated November 08, 2023)
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
0
Attacker Value
Unknown
CVE-2019-12265
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.
0