Vulnerability Description
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Windriver | Vxworks | 6.6 |
| Belden | Hirschmann Hios | <= 07.0.07 |
| Belden | Hirschmann Ees20 | - |
| Belden | Hirschmann Ees25 | - |
| Belden | Hirschmann Eesx20 | - |
| Belden | Hirschmann Eesx30 | - |
| Belden | Hirschmann Grs1020 | - |
| Belden | Hirschmann Grs1030 | - |
| Belden | Hirschmann Grs1042 | - |
| Belden | Hirschmann Grs1120 | - |
| Belden | Hirschmann Grs1130 | - |
| Belden | Hirschmann Grs1142 | - |
| Belden | Hirschmann Msp30 | - |
| Belden | Hirschmann Msp32 | - |
| Belden | Hirschmann Rail Switch Power Lite | - |
| Belden | Hirschmann Rail Switch Power Smart | - |
| Belden | Hirschmann Red25 | - |
| Belden | Hirschmann Rsp20 | - |
| Belden | Hirschmann Rsp25 | - |
| Belden | Hirschmann Rsp30 | - |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdfThird Party Advisory
- https://support.f5.com/csp/article/K41190253Third Party Advisory
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12262Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdfThird Party Advisory
- https://support.f5.com/csp/article/K41190253Third Party Advisory
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12262Vendor Advisory
FAQ
What is CVE-2019-12262?
CVE-2019-12262 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).
How severe is CVE-2019-12262?
CVE-2019-12262 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-12262?
Check the references section above for vendor advisories and patch information. Affected products include: Windriver Vxworks, Belden Hirschmann Hios, Belden Hirschmann Ees20, Belden Hirschmann Ees25, Belden Hirschmann Eesx20.