Vulnerability Description
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls, or manage tasks via requests to UDP port 17185, a related issue to CVE-2005-3804.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | 1756-Enbt\/A Firmware | 3.2.6 |
| Windriver | Vxworks | <= 6.9.4.12 |
| Rockwellautomation | 1756-Enbt\/A | - |
Related Weaknesses (CWE)
References
- http://blog.metasploit.com/2010/08/vxworks-vulnerabilities.htmlNot Applicable
- http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/endusePermissions Required
- http://www.kb.cert.org/vuls/id/362332Third Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86EPFAThird Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86FPQLThird Party AdvisoryUS Government Resource
- https://support.windriver.com/olsPortal/faces/maintenance/downloadDetails.jspx?cPermissions Required
- http://blog.metasploit.com/2010/08/vxworks-vulnerabilities.htmlNot Applicable
- http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/endusePermissions Required
- http://seclists.org/fulldisclosure/2025/Jan/10
- http://www.kb.cert.org/vuls/id/362332Third Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86EPFAThird Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86FPQLThird Party AdvisoryUS Government Resource
- https://support.windriver.com/olsPortal/faces/maintenance/downloadDetails.jspx?cPermissions Required
FAQ
What is CVE-2010-2965?
CVE-2010-2965 is a vulnerability with a CVSS score of 10.0 (HIGH). The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote at...
How severe is CVE-2010-2965?
CVE-2010-2965 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2965?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation 1756-Enbt\/A Firmware, Windriver Vxworks, Rockwellautomation 1756-Enbt\/A.