CVE-2015-7599

Description

Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a username and password.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
6.586

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Wind River VxWorks 5.5Windows
Multiple Vulnerabilities are affected in Wind River VxWorks 6.4Windows
Multiple Vulnerabilities are affected in Wind River VxWorks 6.8Windows
Multiple Vulnerabilities are affected in Wind River VxWorks 6.7Windows
Multiple Vulnerabilities are affected in Wind River VxWorks 6.9Windows
Vulnerabilities CVE-2015-7599 are affected in Wind River VxWorks 6.9.4.1Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234