7.1

CVE-2019-12264

Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WindriverVxworks Version6.6
WindriverVxworks Version6.7
WindriverVxworks Version6.8
WindriverVxworks Version6.9.3
WindriverVxworks Version6.9.4
WindriverVxworks Version7.0
BeldenHirschmann Hios Version <= 07.0.07
   BeldenHirschmann Ees20 Version-
   BeldenHirschmann Ees25 Version-
   BeldenHirschmann Eesx20 Version-
   BeldenHirschmann Eesx30 Version-
   BeldenHirschmann Grs1020 Version-
   BeldenHirschmann Grs1030 Version-
   BeldenHirschmann Grs1042 Version-
   BeldenHirschmann Grs1120 Version-
   BeldenHirschmann Grs1130 Version-
   BeldenHirschmann Grs1142 Version-
   BeldenHirschmann Msp30 Version-
   BeldenHirschmann Msp32 Version-
   BeldenHirschmann Rail Switch Power Lite Version-
   BeldenHirschmann Rail Switch Power Smart Version-
   BeldenHirschmann Red25 Version-
   BeldenHirschmann Rsp20 Version-
   BeldenHirschmann Rsp25 Version-
   BeldenHirschmann Rsp30 Version-
   BeldenHirschmann Rsp35 Version-
   BeldenHirschmann Rspe30 Version-
   BeldenHirschmann Rspe32 Version-
   BeldenHirschmann Rspe35 Version-
   BeldenHirschmann Rspe37 Version-
BeldenHirschmann Hios Version <= 07.5.01
   BeldenHirschmann Msp40 Version-
   BeldenHirschmann Octopus Os3 Version-
BeldenHirschmann Hios Version <= 07.2.04
BeldenHirschmann Hios Version <= 05.3.06
   BeldenHirschmann Eagle One Version-
   BeldenHirschmann Eagle20 Version-
   BeldenHirschmann Eagle30 Version-
BeldenGarrettcom Magnum Dx940e Firmware Version <= 1.0.1_y7
   BeldenGarrettcom Magnum Dx940e Version-
SiemensRuggedcom Win7000 Firmware Version < bs5.2.461.17
   SiemensRuggedcom Win7000 Version-
SiemensRuggedcom Win7018 Firmware Version < bs5.2.461.17
   SiemensRuggedcom Win7018 Version-
SiemensRuggedcom Win7025 Firmware Version < bs5.2.461.17
   SiemensRuggedcom Win7025 Version-
SiemensRuggedcom Win7200 Firmware Version < bs5.2.461.17
   SiemensRuggedcom Win7200 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.486
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 2.8 4.2
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
nvd@nist.gov 4.8 6.5 4.9
AV:A/AC:L/Au:N/C:N/I:P/A:P
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.