Back

CVE-2019-12255

CRITICAL

Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.

Published: Aug 9, 2019 Modified: Jun 17, 2026
CWE-120

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (32)

Vendor Product Version
windriver vxworks * ≥ 6.5 < 6.9.4
netapp e-series_santricity_os_controller * ≥ 8.00
sonicwall sonicos * ≥ 5.9.0.0
sonicwall sonicos * ≥ 5.9.1.0.
sonicwall sonicos * ≥ 6.2.0.0
sonicwall sonicos * ≥ 6.2.4.0
sonicwall sonicos * ≥ 6.2.5.0
sonicwall sonicos * ≥ 6.2.6.0
sonicwall sonicos * ≥ 6.2.7.0
sonicwall sonicos * ≥ 6.2.9.0
sonicwall sonicos * ≥ 6.5.0.0
sonicwall sonicos * ≥ 6.5.1.0
sonicwall sonicos * ≥ 6.5.2.0
sonicwall sonicos * ≥ 6.5.3.0
sonicwall sonicos * ≥ 6.5.4.0.
sonicwall sonicos 6.2.7.0
sonicwall sonicos 6.2.7.1
sonicwall sonicos 6.2.7.7
siemens siprotec_5_firmware * < 7.91
siemens siprotec_5_firmware *

…and 12 more

GitHub Security Advisory GHSA-h297-57pm-6g4c

Wind River VxWorks 6.5 through 6.9.3 has a Buffer Overflow in the TCP component (issue 1 of 4)....

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 75.25%

Top 1% most likely to be exploited

Threat Score 71.8 / 100

Data Sources

NVD EPSS GitHub