HIGH · 7.1

CVE-2019-12264

Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

Vulnerability Description

Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

CVSS Score

7.1

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
WindriverVxworks6.6
BeldenHirschmann Hios<= 07.0.07
BeldenHirschmann Ees20-
BeldenHirschmann Ees25-
BeldenHirschmann Eesx20-
BeldenHirschmann Eesx30-
BeldenHirschmann Grs1020-
BeldenHirschmann Grs1030-
BeldenHirschmann Grs1042-
BeldenHirschmann Grs1120-
BeldenHirschmann Grs1130-
BeldenHirschmann Grs1142-
BeldenHirschmann Msp30-
BeldenHirschmann Msp32-
BeldenHirschmann Rail Switch Power Lite-
BeldenHirschmann Rail Switch Power Smart-
BeldenHirschmann Red25-
BeldenHirschmann Rsp20-
BeldenHirschmann Rsp25-
BeldenHirschmann Rsp30-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-12264?

CVE-2019-12264 is a vulnerability with a CVSS score of 7.1 (HIGH). Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

How severe is CVE-2019-12264?

CVE-2019-12264 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-12264?

Check the references section above for vendor advisories and patch information. Affected products include: Windriver Vxworks, Belden Hirschmann Hios, Belden Hirschmann Ees20, Belden Hirschmann Ees25, Belden Hirschmann Eesx20.