peter bassill · operator
$ cve CVE-2019-12262 JSON

CVE-2019-12262

9.8
CRITICAL · CVSS 3.1 · EPSS 4.1% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.12% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploitnone known
Published2019-08-14
Last modified2026-06-17

Affected (40)

VendorProduct
beldengarrettcom magnum dx940e
beldengarrettcom magnum dx940e firmware
beldenhirschmann dragon mach4000
beldenhirschmann dragon mach4500
beldenhirschmann eagle one
beldenhirschmann eagle20
beldenhirschmann eagle30
beldenhirschmann ees20
beldenhirschmann ees25
beldenhirschmann eesx20
beldenhirschmann eesx30
beldenhirschmann grs1020
beldenhirschmann grs1030
beldenhirschmann grs1042
beldenhirschmann grs1120
beldenhirschmann grs1130
beldenhirschmann grs1142
beldenhirschmann hios
beldenhirschmann msp30
beldenhirschmann msp32
beldenhirschmann msp40
beldenhirschmann octopus os3
beldenhirschmann rail switch power lite
beldenhirschmann rail switch power smart
beldenhirschmann red25
beldenhirschmann rsp20
beldenhirschmann rsp25
beldenhirschmann rsp30
beldenhirschmann rsp35
beldenhirschmann rspe30
beldenhirschmann rspe32
beldenhirschmann rspe35
beldenhirschmann rspe37
siemensruggedcom win7000
siemensruggedcom win7000 firmware
siemensruggedcom win7018
siemensruggedcom win7018 firmware
siemensruggedcom win7025
siemensruggedcom win7025 firmware
windrivervxworks

References

→ the Explorer  ·  watch your stack  ·  NVD