CVE-2019-12263
published 2019-08-09CVE-2019-12263: Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state…
PriorityP276high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.19%
86.7th percentile
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| belden | garrettcom_magnum_dx940e_firmware | <= 1.0.1_y7 | — |
| belden | hirschmann_hios | <= 07.0.07 | — |
| belden | hirschmann_hios | <= 07.5.01 | — |
| belden | hirschmann_hios | <= 07.2.04 | — |
| belden | hirschmann_hios | <= 05.3.06 | — |
| netapp | e-series_santricity_os_controller | 8.00 – 8.40.50.00 | — |
| siemens | power_meter_9410_firmware | < 2.2.1 | 2.2.1 |
| siemens | ruggedcom_win7000_firmware | < bs5.2.461.17 | bs5.2.461.17 |
| siemens | ruggedcom_win7018_firmware | < bs5.2.461.17 | bs5.2.461.17 |
| siemens | ruggedcom_win7025_firmware | < bs5.2.461.17 | bs5.2.461.17 |
| siemens | ruggedcom_win7200_firmware | < bs5.2.461.17 | bs5.2.461.17 |
| siemens | siprotec_5_firmware | < 7.59 | 7.59 |
| siemens | siprotec_5_firmware | < 7.91 | 7.91 |
| sonicwall | sonicos | — | — |
| sonicwall | sonicos | — | — |
| sonicwall | sonicos | — | — |
| sonicwall | sonicos | 5.9.0.0 – 5.9.0.7 | — |
| sonicwall | sonicos | 5.9.1.0. – 5.9.1.12 | — |
| sonicwall | sonicos | 6.2.0.0 – 6.2.3.1 | — |
| sonicwall | sonicos | 6.2.4.0 – 6.2.4.3 | — |
| sonicwall | sonicos | 6.2.5.0 – 6.2.5.3 | — |
| sonicwall | sonicos | 6.2.6.0 – 6.2.6.1 | — |
| sonicwall | sonicos | 6.2.7.0 – 6.2.7.4 | — |
| sonicwall | sonicos | 6.2.9.0 – 6.2.9.2 | — |
| sonicwall | sonicos | 6.5.0.0 – 6.5.0.3 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target is the TCP/IP stack (IPNET) in Wind River VxWorks 6.9.4 and vx7; the vulnerability is a buffer overflow triggered by TCP Urgent Pointer state confusion due to a race condition — focus network detection on malformed TCP segments with anomalous Urgent Pointer values sent to VxWorks-based devices. ↗
- ·Vulnerability affects specifically VxWorks versions 6.9.4 and vx7; detections and mitigations should be scoped to these versions of the IPNET TCP/IP stack component. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-34m3-97v7-926m: Wind River VxWorks 6
ghsa_unreviewed·2022-05-24
CVE-2019-12263 [HIGH] CWE-119 GHSA-34m3-97v7-926m: Wind River VxWorks 6
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
VulnCheck
windriver vxworks Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
vulncheck·2019·CVSS 8.1
CVE-2019-12263 [HIGH] windriver vxworks Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
windriver vxworks Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
Affected: windriver vxworks
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://cyble.com/blog/weekly-cyble-vulnerability-blog/
CISA ICS
Interpeak IPnet TCP/IP Stack (Update E)
cisa_ics·2024-09-24·CVSS 9.8
[CRITICAL] Interpeak IPnet TCP/IP Stack (Update E)
ICS Advisory
##
Interpeak IPnet TCP/IP Stack (Update E)
Last RevisedSeptember 24, 2024
Alert CodeICSA-19-274-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: ENEA, Green Hills Software, ITRON, IP Infusion, Wind River
- Equipment: OSE by ENEA, INTEGRITY RTOS by Green Hills Software, ITRON, ZebOS by IP Infusion, and VxWorks by Wind River
- Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow, Integer Underflow (Wrap or Wraparound), Improper Restriction of Operations within the Bounds of a Memory Buffer, Concurrent Execution using Shared Resource with Improp
CISA ICS
Siemens SIPROTEC 4 7SJ66
cisa_ics·2023-11-16·CVSS 9.8
[CRITICAL] Siemens SIPROTEC 4 7SJ66
ICS Advisory
##
Siemens SIPROTEC 4 7SJ66
Release DateNovember 16, 2023
Alert CodeICSA-23-320-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIPROTEC 4 7SJ66
- Vulnerabilities: Classic Buffer Overflow, Session Fixation, NULL Pointer Dereference, Origin Validation Error, Race Condition, Missing Release of Memory after Effective Lifetime
## 2. RISK EVALUATION
CISA ICS
Wind River VxWorks (Update A)
cisa_ics·2019-07-30·CVSS 9.8
[CRITICAL] Wind River VxWorks (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Wind River VxWorks (Update A)
Last RevisedOctober 05, 2020
Alert CodeICSA-19-211-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Wind River
- Equipment: VxWorks
- Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow, Integer Underflow, Improper Restriction of Operations within the Bounds of a Memory Buffer, Race Condition, Argument Condition or Modification, Null Pointer Dereference, Argument Injection or Modification
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the orig
No detection rules found.
No public exploits indexed.
Tenable
Critical Vulnerabilities Dubbed URGENT/11 Place Devices Running VxWorks at Risk of RCE Attacks
blogs_tenable·2019-07-29
Critical Vulnerabilities Dubbed URGENT/11 Place Devices Running VxWorks at Risk of RCE Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Huntress
What Is a Race Condition? Types, Causes & Security Impact | Huntress
blogs_huntress
What Is a Race Condition? Types, Causes & Security Impact | Huntress
## Table of Contents
What is a Race Condition?
What Causes Race Conditions?
Types of Race Conditions
Why Do Race Conditions Matter in Cybersecurity?
Real-World Examples of Race Conditions
How to Detect Race Conditions
Best Practices for Mitigating Race Conditions
Frequently Asked Questions (FAQs)
## What is a race condition?
A race condition occurs when the outcome of a program or process depends on the timing or sequence of multiple threads or processes that are accessing and modifying shared resources. This lack of proper synchronization creates unpredictable behavior, which can lead to security vulnerabilities, data inconsistencies, and system instability.
## Example breakdown
Imagine two threads in a banking system trying to withdraw from the same account balance. Without p
https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdfhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009https://security.netapp.com/advisory/ntap-20190802-0001/https://support.f5.com/csp/article/K41190253https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12263https://support2.windriver.com/index.php?page=security-noticeshttps://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdfhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009https://security.netapp.com/advisory/ntap-20190802-0001/https://support.f5.com/csp/article/K41190253https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12263https://support2.windriver.com/index.php?page=security-noticeshttps://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
2019-08-09
Published
Exploited in the wild