CVE-2019-12263

Description

Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.547

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-3963,CVE-2019-12263,CVE-2019-12264,CVE-2019-12265 are affected in Wind River VxWorks 6.9.4Windows
Multiple Vulnerabilities are affected in Wind River VxWorks 7Windows
Multiple Vulnerabilities are affected in Wind River VxWorks 7.0Windows
Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) Vulnerability (CVE-2019-12263)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234