cbcvebase.

Wind River Systems Inc Vxworks 7 vulnerabilities

4 known vulnerabilities affecting wind_river_systems_inc/vxworks_7.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-104018P2HIGHCVSS 8.8vVxWorks 72026-10-01
CVE-2026-104018 [HIGH] CWE-269 CVE-2026-104018: An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River V An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with limited privileges to execute command
nvd
CVE-2026-102004P3HIGHCVSS 7.8vVxWorks 72026-09-28
CVE-2026-102004 [HIGH] CWE-787 CVE-2026-102004: Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09
nvd
CVE-2025-26503P4MEDIUMCVSS 6.7≥ 7.0.0, < 25.032025-09-18
CVE-2025-26503 [MEDIUM] CWE-119 CVE-2025-26503: A crafted system call argument can cause memory corruption. A crafted system call argument can cause memory corruption.
nvd
CVE-2026-102006P4MEDIUMCVSS 5.5vVxWorks 72026-09-28
CVE-2026-102006 [MEDIUM] CWE-401 CVE-2026-102006: In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process man In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed in Version 26.09
nvd
Wind River Systems Inc Vxworks 7 vulnerabilities | cvebase