Back

CVE-2019-12261

CRITICAL

Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.

Published: Aug 9, 2019 Modified: Jun 17, 2026
CWE-120

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (33)

Vendor Product Version
windriver vxworks * ≥ 6.5 < 6.9.4.12
windriver vxworks 7.0
sonicwall sonicos * ≥ 5.9.0.0
sonicwall sonicos * ≥ 5.9.1.0.
sonicwall sonicos * ≥ 6.2.0.0
sonicwall sonicos * ≥ 6.2.4.0
sonicwall sonicos * ≥ 6.2.5.0
sonicwall sonicos * ≥ 6.2.6.0
sonicwall sonicos * ≥ 6.2.7.0
sonicwall sonicos * ≥ 6.2.9.0
sonicwall sonicos * ≥ 6.5.0.0
sonicwall sonicos * ≥ 6.5.1.0
sonicwall sonicos * ≥ 6.5.2.0
sonicwall sonicos * ≥ 6.5.3.0
sonicwall sonicos * ≥ 6.5.4.0.
sonicwall sonicos 6.2.7.0
sonicwall sonicos 6.2.7.1
sonicwall sonicos 6.2.7.7
siemens siprotec_5_firmware * < 7.59
netapp e-series_santricity_os_controller * ≥ 8.00

…and 13 more

GitHub Security Advisory GHSA-745f-4hrc-c6hf

Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 8.97%

Top 5% most likely to be exploited

Threat Score 41.9 / 100

Data Sources

NVD EPSS GitHub