8.8

CVE-2019-12257

Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WindriverVxworks Version >= 6.5 < 6.9.4
SonicwallSonicos Version >= 5.9.0.0 <= 5.9.0.7
SonicwallSonicos Version >= 5.9.1.0. <= 5.9.1.12
SonicwallSonicos Version >= 6.2.0.0 <= 6.2.3.1
SonicwallSonicos Version >= 6.2.4.0 <= 6.2.4.3
SonicwallSonicos Version >= 6.2.5.0 <= 6.2.5.3
SonicwallSonicos Version >= 6.2.6.0 <= 6.2.6.1
SonicwallSonicos Version >= 6.2.7.0 <= 6.2.7.4
SonicwallSonicos Version >= 6.2.9.0 <= 6.2.9.2
SonicwallSonicos Version >= 6.5.0.0 <= 6.5.0.3
SonicwallSonicos Version >= 6.5.1.0 <= 6.5.1.4
SonicwallSonicos Version >= 6.5.2.0 <= 6.5.2.3
SonicwallSonicos Version >= 6.5.3.0 <= 6.5.3.3
SonicwallSonicos Version >= 6.5.4.0. <= 6.5.4.3
SonicwallSonicos Version6.2.7.0
SonicwallSonicos Version6.2.7.1
SonicwallSonicos Version6.2.7.7
SiemensSiprotec 5 Firmware Version < 7.59
   SiemensSiprotec 5 Version-
NetappE-series Santricity Os Controller Version >= 8.00 <= 8.40.50.00
SiemensSiprotec 5 Firmware Version < 7.91
   SiemensSiprotec 5 Version-
SiemensRuggedcom Win7000 Firmware Version < bs5.2.461.17
   SiemensRuggedcom Win7000 Version-
SiemensRuggedcom Win7018 Firmware Version < bs5.2.461.17
   SiemensRuggedcom Win7018 Version-
SiemensRuggedcom Win7025 Firmware Version < bs5.2.461.17
   SiemensRuggedcom Win7025 Version-
SiemensRuggedcom Win7200 Firmware Version < bs5.2.461.17
   SiemensRuggedcom Win7200 Version-
BeldenHirschmann Hios Version <= 07.0.07
   BeldenHirschmann Ees20 Version-
   BeldenHirschmann Ees25 Version-
   BeldenHirschmann Eesx20 Version-
   BeldenHirschmann Eesx30 Version-
   BeldenHirschmann Grs1020 Version-
   BeldenHirschmann Grs1030 Version-
   BeldenHirschmann Grs1042 Version-
   BeldenHirschmann Grs1120 Version-
   BeldenHirschmann Grs1130 Version-
   BeldenHirschmann Grs1142 Version-
   BeldenHirschmann Msp30 Version-
   BeldenHirschmann Msp32 Version-
   BeldenHirschmann Rail Switch Power Lite Version-
   BeldenHirschmann Rail Switch Power Smart Version-
   BeldenHirschmann Red25 Version-
   BeldenHirschmann Rsp20 Version-
   BeldenHirschmann Rsp25 Version-
   BeldenHirschmann Rsp30 Version-
   BeldenHirschmann Rsp35 Version-
   BeldenHirschmann Rspe30 Version-
   BeldenHirschmann Rspe32 Version-
   BeldenHirschmann Rspe35 Version-
   BeldenHirschmann Rspe37 Version-
BeldenHirschmann Hios Version <= 07.5.01
   BeldenHirschmann Msp40 Version-
   BeldenHirschmann Octopus Os3 Version-
BeldenHirschmann Hios Version <= 07.2.04
BeldenHirschmann Hios Version <= 05.3.06
   BeldenHirschmann Eagle One Version-
   BeldenHirschmann Eagle20 Version-
   BeldenHirschmann Eagle30 Version-
BeldenGarrettcom Magnum Dx940e Firmware Version <= 1.0.1_y7
   BeldenGarrettcom Magnum Dx940e Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 15.36% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.8 6.5 6.4
AV:A/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.