HIGH · 7.5

CVE-2019-12259

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

Vulnerability Description

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
WindriverVxworks>= 6.5, < 6.9.4.12
SonicwallSonicos>= 5.9.0.0, <= 5.9.0.7
SiemensSiprotec 5 Firmware< 7.59
SiemensSiprotec 5-
SiemensRuggedcom Win7000 Firmware< bs5.2.461.17
SiemensRuggedcom Win7000-
SiemensRuggedcom Win7200 Firmware< bs5.2.461.17
SiemensRuggedcom Win7200-
SiemensRuggedcom Win7025 Firmware< bs5.2.461.17
SiemensRuggedcom Win7025-
SiemensRuggedcom Win7018 Firmware< bs5.2.461.17
SiemensRuggedcom Win7018-
Siemens9410 Power Meter Firmware< 2.2.1
Siemens9410 Power Meter-
Siemens9810 Power Meter Firmware< 2.2.1
Siemens9810 Power Meter-
BeldenHirschmann Hios<= 07.0.07
BeldenHirschmann Ees20-
BeldenHirschmann Ees25-
BeldenHirschmann Eesx20-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-12259?

CVE-2019-12259 is a vulnerability with a CVSS score of 7.5 (HIGH). Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

How severe is CVE-2019-12259?

CVE-2019-12259 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-12259?

Check the references section above for vendor advisories and patch information. Affected products include: Windriver Vxworks, Sonicwall Sonicos, Siemens Siprotec 5 Firmware, Siemens Siprotec 5, Siemens Ruggedcom Win7000 Firmware.