Back

CVE-2019-12256

CRITICAL

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.

Published: Aug 9, 2019 Modified: Jun 17, 2026
CWE-120

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (31)

Vendor Product Version
windriver vxworks * ≥ 6.5 < 6.9.4.12
netapp e-series_santricity_os_controller * ≥ 8.00
sonicwall sonicos * ≥ 5.9.0.0
sonicwall sonicos * ≥ 5.9.1.0.
sonicwall sonicos * ≥ 6.2.0.0
sonicwall sonicos * ≥ 6.2.4.0
sonicwall sonicos * ≥ 6.2.5.0
sonicwall sonicos * ≥ 6.2.6.0
sonicwall sonicos * ≥ 6.2.7.0
sonicwall sonicos * ≥ 6.2.9.0
sonicwall sonicos * ≥ 6.5.0.0
sonicwall sonicos * ≥ 6.5.1.0
sonicwall sonicos * ≥ 6.5.2.0
sonicwall sonicos * ≥ 6.5.3.0
sonicwall sonicos * ≥ 6.5.4.0.
sonicwall sonicos 6.2.7.0
sonicwall sonicos 6.2.7.1
sonicwall sonicos 6.2.7.7
siemens siprotec_5_firmware * < 7.59
siemens siprotec_5_firmware * < 7.91

…and 11 more

GitHub Security Advisory GHSA-5g99-hg5x-7m26

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 26.63%

Top 2% most likely to be exploited

Threat Score 47.2 / 100

Data Sources

NVD EPSS GitHub