CVE-2019-12258
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 23%
from disclosure to weapon0 days
Published on NVDAug 9
metasploitAug 9
exploitation probability
23%top 2% of all CVEs
observed exploitation
nono source reports it
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
Affected products
n/a · n/aReferences
https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdfhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009https://security.netapp.com/advisory/ntap-20190802-0001/https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12258https://support2.windriver.com/index.php?page=security-noticeshttps://support.f5.com/csp/article/K41190253https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/