CVE-2015-7599

HIGH

Wind River VxWorks <6.9.4.1 - DoS/Code Injection

Title source: llm
STIX 2.1

Description

Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a username and password.

Scores

CVSS v3 8.1
EPSS 0.0591
EPSS Percentile 92.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (6)
windriver/vxworks 5.5
windriver/vxworks 6.4
windriver/vxworks 6.7
windriver/vxworks 6.8
windriver/vxworks 6.9
windriver/vxworks < 6.9.4.1
Published Feb 07, 2017
Tracked Since Feb 18, 2026