MEDIUM · 5.8

CVE-2015-3963

Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices bef...

Vulnerability Description

Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices before J2 and other devices, does not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

CVSS Score

5.8

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
WindriverVxworks>= 6.5, <= 6.6
Schneider-ElectricSage 1210-
Schneider-ElectricSage 1230-
Schneider-ElectricSage 1250-
Schneider-ElectricSage 1310-
Schneider-ElectricSage 1330-
Schneider-ElectricSage 1350-
Schneider-ElectricSage 1410-
Schneider-ElectricSage 1430-
Schneider-ElectricSage 1450-
Schneider-ElectricSage 2200-
Schneider-ElectricSage 2400-
Schneider-ElectricSage 3030-
Schneider-ElectricSage 3030 Magnum-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3963?

CVE-2015-3963 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices bef...

How severe is CVE-2015-3963?

CVE-2015-3963 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3963?

Check the references section above for vendor advisories and patch information. Affected products include: Windriver Vxworks, Schneider-Electric Sage 1210, Schneider-Electric Sage 1230, Schneider-Electric Sage 1250, Schneider-Electric Sage 1310.