CVE-2019-12255
published 2019-08-09CVE-2019-12255: Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an…
PriorityP189critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
75.25%
99.5th percentile
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| belden | garrettcom_magnum_dx940e_firmware | <= 1.0.1_y7 | — |
| belden | hirschmann_hios | <= 07.0.07 | — |
| belden | hirschmann_hios | <= 07.5.01 | — |
| belden | hirschmann_hios | <= 07.2.04 | — |
| belden | hirschmann_hios | <= 05.3.06 | — |
| netapp | e-series_santricity_os_controller | 8.00 – 8.40.50.00 | — |
| siemens | power_meter_9410_firmware | < 2.2.1 | 2.2.1 |
| siemens | ruggedcom_win7000_firmware | < bs5.2.461.17 | bs5.2.461.17 |
| siemens | ruggedcom_win7018_firmware | < bs5.2.461.17 | bs5.2.461.17 |
| siemens | ruggedcom_win7025_firmware | < bs5.2.461.17 | bs5.2.461.17 |
| siemens | ruggedcom_win7200_firmware | < bs5.2.461.17 | bs5.2.461.17 |
| siemens | siprotec_5_firmware | < 7.91 | 7.91 |
| sonicwall | sonicos | — | — |
| sonicwall | sonicos | — | — |
| sonicwall | sonicos | — | — |
| sonicwall | sonicos | 5.9.0.0 – 5.9.0.7 | — |
| sonicwall | sonicos | 5.9.1.0. – 5.9.1.12 | — |
| sonicwall | sonicos | 6.2.0.0 – 6.2.3.1 | — |
| sonicwall | sonicos | 6.2.4.0 – 6.2.4.3 | — |
| sonicwall | sonicos | 6.2.5.0 – 6.2.5.3 | — |
| sonicwall | sonicos | 6.2.6.0 – 6.2.6.1 | — |
| sonicwall | sonicos | 6.2.7.0 – 6.2.7.4 | — |
| sonicwall | sonicos | 6.2.9.0 – 6.2.9.2 | — |
| sonicwall | sonicos | 6.5.0.0 – 6.5.0.3 | — |
| sonicwall | sonicos | 6.5.1.0 – 6.5.1.4 | — |
Detection & IOCsextracted from sources · hover to see the quote
commandIP(dst=ip)/TCP(sport=sport, dport=dport, flags="PAU", seq=seq_num, ack=ack_num, urgptr=0) / payload↗
- →Detect TCP segments with the URG+PSH+ACK flags set (flags='PAU') and an Urgent Pointer value of exactly 0, which is the trigger condition for the integer underflow in VxWorks IPNET TCP stack. ↗
- →The exploit targets VxWorks services listening on TCP (e.g., telnet port 23, FTP) — monitor for large payloads (~2000 bytes) sent with URG flag and urgptr=0 to these ports. ↗
- →The vulnerability is in the IPNET TCP component of VxWorks 6.8; a TCP Urgent Pointer value of 0 leads to an integer underflow — alert on TCP URG packets where urgptr==0 directed at VxWorks devices. ↗
- ·The PoC was tested specifically against VxWorks 6.8; applicability to other VxWorks versions should be verified before using this as a detection baseline. ↗
- ·The exploit targets any TCP port hosting a VxWorks task (e.g., telnet on 23, FTP); defenders should apply detection broadly across all open TCP ports on VxWorks devices, not only port 23. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h297-57pm-6g4c: Wind River VxWorks 6
ghsa_unreviewed·2022-05-24
CVE-2019-12255 [CRITICAL] CWE-119 GHSA-h297-57pm-6g4c: Wind River VxWorks 6
Wind River VxWorks 6.5 through 6.9.3 has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. Affected versions: 6.6, 6.7, 6.8, 6.9
VulnCheck
windriver vxworks Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
vulncheck·2019·CVSS 9.8
CVE-2019-12255 [CRITICAL] windriver vxworks Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
windriver vxworks Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
Affected: windriver vxworks
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://cyble.com/blog/weekly-cyble-vulnerability-blog/
CISA ICS
Interpeak IPnet TCP/IP Stack (Update E)
cisa_ics·2024-09-24·CVSS 9.8
[CRITICAL] Interpeak IPnet TCP/IP Stack (Update E)
ICS Advisory
##
Interpeak IPnet TCP/IP Stack (Update E)
Last RevisedSeptember 24, 2024
Alert CodeICSA-19-274-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: ENEA, Green Hills Software, ITRON, IP Infusion, Wind River
- Equipment: OSE by ENEA, INTEGRITY RTOS by Green Hills Software, ITRON, ZebOS by IP Infusion, and VxWorks by Wind River
- Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow, Integer Underflow (Wrap or Wraparound), Improper Restriction of Operations within the Bounds of a Memory Buffer, Concurrent Execution using Shared Resource with Improp
CISA ICS
Siemens SIPROTEC 4 7SJ66
cisa_ics·2023-11-16·CVSS 9.8
[CRITICAL] Siemens SIPROTEC 4 7SJ66
ICS Advisory
##
Siemens SIPROTEC 4 7SJ66
Release DateNovember 16, 2023
Alert CodeICSA-23-320-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIPROTEC 4 7SJ66
- Vulnerabilities: Classic Buffer Overflow, Session Fixation, NULL Pointer Dereference, Origin Validation Error, Race Condition, Missing Release of Memory after Effective Lifetime
## 2. RISK EVALUATION
CISA ICS
Wind River VxWorks (Update A)
cisa_ics·2019-07-30·CVSS 9.8
[CRITICAL] Wind River VxWorks (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Wind River VxWorks (Update A)
Last RevisedOctober 05, 2020
Alert CodeICSA-19-211-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Wind River
- Equipment: VxWorks
- Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow, Integer Underflow, Improper Restriction of Operations within the Bounds of a Memory Buffer, Race Condition, Argument Condition or Modification, Null Pointer Dereference, Argument Injection or Modification
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the orig
No detection rules found.
Unit42
Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare Organization
blogs_unit42·2022-03-02
Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare Organization
Threat Research Center
Threat Research
Vulnerabilities
## Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare Organization
Aveek Das
Published: March 2, 2022
Threat Research
Vulnerabilities
Healthcare
IoMT
IoT
## Executive Summary
Unit 42 recently set out to better understand how well hospitals and other healthcare providers are doing in securing smart infusion pumps, which are network-connected devices that deliver medications and fluids to patients. This topic is of critical concern because security lapses in these devices have the potential to put lives at risk or expose sensitive patient data.
We reviewed crowdsourced data from scans of more than 200,000 infusion pumps on the networks of hospitals and other healthcare organizations using IoT Security for
Unit42
Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare Organization
blogs_unit42·2022-03-02
Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare Organization
## Executive Summary
Unit 42 recently set out to better understand how well hospitals and other healthcare providers are doing in securing smart infusion pumps, which are network-connected devices that deliver medications and fluids to patients. This topic is of critical concern because security lapses in these devices have the potential to put lives at risk or expose sensitive patient data.
We reviewed crowdsourced data from scans of more than 200,000 infusion pumps on the networks of hospitals and other healthcare organizations using IoT Security for Healthcare from Palo Alto Networks. An alarming 75 percent of infusion pumps scanned had known security gaps that put them at heightened risk of being compromised by attackers. These shortcomings included exposure to one or more of some 40
Tenable
Critical Vulnerabilities Dubbed URGENT/11 Place Devices Running VxWorks at Risk of RCE Attacks
blogs_tenable·2019-07-29
Critical Vulnerabilities Dubbed URGENT/11 Place Devices Running VxWorks at Risk of RCE Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
FuzzBox: Blending Fuzzing into Emulation for Binary-Only Embedded Targets
arxiv_fulltext·2025-09-06
FuzzBox: Blending Fuzzing into Emulation for Binary-Only Embedded Targets
[FuzzBox: Blending Fuzzing into Emulation \ Binary-Only Embedded Targets]FuzzBox: Blending Fuzzing into Emulation for Binary-Only Embedded Targets
Carmine Cesarano\carmine.cesarano2, roberto.natella\@unina.it
Roberto Natella
DIETI, Università degli Studi di Napoli Federico II, Naples, Italy
Coverage-guided fuzzing has been widely applied to address zero-day vulnerabilities in general-purpose software and operating systems. This approach relies on instrumenting the target code at compile time. However, applying it to industrial systems remains challenging, due to proprietary and closed-source compiler toolchains and lack of access to source code. addresses these limitations by integrating emulation with fuzzing: it dynamically instruments code during execution in a virtualized environme
arXiv
Identifying Key Expert Actors in Cybercrime Forums Based on their Technical Expertise
arxiv_fulltext·2025-06-03
Identifying Key Expert Actors in Cybercrime Forums Based on their Technical Expertise
Identifying Key Expert Actors in Cybercrime Forums Based on their Technical ExpertiseStudy published in the 2024 APWG Symposium on Electronic Crime Research (eCrime) available at: www.doi.org/10.1109/eCrime66200.2024.00019
Estelle Ruellan
Université de Montréal
Flare
Canada
François Labrèche
Secureworks
Canada
Masarah Paquet-Clouston
Université de Montréal
Complexity Science Hub
Canada
Study published in the 2024 APWG Symposium on Electronic Crime Research (eCrime) available at: www.doi.org/10.1109/eCrime66200.2024.00019. © 2025 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective wor
arXiv
Firmware Re-hosting Through Static Binary-level Porting
arxiv_fulltext·2021-07-29
Firmware Re-hosting Through Static Binary-level Porting
Firmware Re-hosting
Through Static Binary-level Porting
[1]Mingfeng Xin
[1]Hui Wen
[1]Liting Deng
[1]Hong Li
[2]Qiang Li
[1]Limin Sun
[1]Institute of Information Engineering, CAS, China
[2]School of Computer and Information Technology, Beijing Jiaotong University, China
[ ]\xinmingfeng,wenhui,dengliting,lihong,sunlimin\@iie.ac.cn, [email protected]
## Abstract
The rapid growth of the Industrial Internet of Things (IIoT) has brought embedded systems into focus as major targets for both security analysts and malicious adversaries. Due to the non-standard hardware and diverse software, embedded devices present unique challenges to security analysts for the accurate analysis of firmware binaries. The diversity in hardware components and tight coupling between firmware and hardware make
http://packetstormsecurity.com/files/154022/VxWorks-6.8-Integer-Underflow.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdfhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009https://security.netapp.com/advisory/ntap-20190802-0001/https://support.f5.com/csp/article/K41190253https://support.f5.com/csp/article/K41190253?utm_source=f5support&%3Butm_medium=RSShttps://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12255https://support2.windriver.com/index.php?page=security-noticeshttps://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/http://packetstormsecurity.com/files/154022/VxWorks-6.8-Integer-Underflow.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdfhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009https://security.netapp.com/advisory/ntap-20190802-0001/https://support.f5.com/csp/article/K41190253https://support.f5.com/csp/article/K41190253?utm_source=f5support&%3Butm_medium=RSShttps://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12255https://support2.windriver.com/index.php?page=security-noticeshttps://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
2019-08-09
Published
Exploited in the wild