Vulnerability Description
Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Windriver | Vxworks | 6.6 |
| Belden | Hirschmann Hios | <= 07.0.07 |
| Belden | Hirschmann Ees20 | - |
| Belden | Hirschmann Ees25 | - |
| Belden | Hirschmann Eesx20 | - |
| Belden | Hirschmann Eesx30 | - |
| Belden | Hirschmann Grs1020 | - |
| Belden | Hirschmann Grs1030 | - |
| Belden | Hirschmann Grs1042 | - |
| Belden | Hirschmann Grs1120 | - |
| Belden | Hirschmann Grs1130 | - |
| Belden | Hirschmann Grs1142 | - |
| Belden | Hirschmann Msp30 | - |
| Belden | Hirschmann Msp32 | - |
| Belden | Hirschmann Rail Switch Power Lite | - |
| Belden | Hirschmann Rail Switch Power Smart | - |
| Belden | Hirschmann Red25 | - |
| Belden | Hirschmann Rsp20 | - |
| Belden | Hirschmann Rsp25 | - |
| Belden | Hirschmann Rsp30 | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfThird Party Advisory
- https://support.f5.com/csp/article/K41190253Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeThird Party Advisory
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12264Vendor Advisory
- https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgeVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfThird Party Advisory
- https://support.f5.com/csp/article/K41190253Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeThird Party Advisory
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12264Vendor Advisory
- https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgeVendor Advisory
FAQ
What is CVE-2019-12264?
CVE-2019-12264 is a vulnerability with a CVSS score of 7.1 (HIGH). Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.
How severe is CVE-2019-12264?
CVE-2019-12264 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12264?
Check the references section above for vendor advisories and patch information. Affected products include: Windriver Vxworks, Belden Hirschmann Hios, Belden Hirschmann Ees20, Belden Hirschmann Ees25, Belden Hirschmann Eesx20.