vendor:
VxWorks
by:
Zhou Yu
9.8
CVSS
CRITICAL
Integer Underflow
190
CWE
Product Name: VxWorks
Affected Version From: VxWorks 6.8
Affected Version To: VxWorks 6.8
Patch Exists: YES
Related CWE: CVE-2019-12255
CPE: o:windriver:vxworks:6.8
Other Scripts:
N/A
Platforms Tested: None
2019
VxWorks TCP Urgent pointer = 0 integer underflow vulnerability
The PoC can crash VxWorks tasks(set the port corresponding to the task in the PoC), such as telnet, ftp, etc.
Mitigation:
Upgrade to the latest version of VxWorks 6.8