ID

VAR-201509-0500


TITLE

Wind River VxWorks Integer Overflow Vulnerability

Trust: 0.8

sources: IVD: adb3b682-1e64-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-06243

DESCRIPTION

VxWorks is a real-time operating system widely used on ICS-related devices. Wind River VxWorks version 5.5-6.9.4.1 has an integer overflow vulnerability in its implementation. Successful use allows an attacker to remotely execute arbitrary code in the operating system, destroy or bypass all memory protection, and set up backdoor accounts

Trust: 0.72

sources: CNVD: CNVD-2015-06243 // IVD: adb3b682-1e64-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: adb3b682-1e64-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-06243

AFFECTED PRODUCTS

vendor:wind rivermodel:vxworksscope:eqversion:5.5-6.9.4.1

Trust: 0.8

sources: IVD: adb3b682-1e64-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-06243

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2015-06243
value: MEDIUM

Trust: 0.6

IVD: adb3b682-1e64-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2015-06243
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: adb3b682-1e64-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: adb3b682-1e64-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-06243

TYPE

Number error

Trust: 0.2

sources: IVD: adb3b682-1e64-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:CNVDid:CNVD-2015-06243

Trust: 0.8

db:NSFOCUSid:30916

Trust: 0.6

db:IVDid:ADB3B682-1E64-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: adb3b682-1e64-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-06243

REFERENCES

url:http://www.nsfocus.net/vulndb/30916

Trust: 0.6

sources: CNVD: CNVD-2015-06243

SOURCES

db:IVDid:adb3b682-1e64-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2015-06243

LAST UPDATE DATE

2022-05-17T02:07:08.248000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-06243date:2015-09-29T00:00:00

SOURCES RELEASE DATE

db:IVDid:adb3b682-1e64-11e6-abef-000c29c66e3ddate:2015-09-29T00:00:00
db:CNVDid:CNVD-2015-06243date:2015-09-28T00:00:00