CVE-2019-12260

Description

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
25.599

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Wind River VxWorks 6.9Windows
Multiple Vulnerabilities are affected in Wind River VxWorks 7Windows
Multiple Vulnerabilities are affected in Wind River VxWorks 7.0Windows
Buffer Copy without Checking Size of Input (Classic Buffer Overflow) Vulnerability (CVE-2019-12260)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234