CVE-2019-12258
HIGHURGENT/11 Scanner, Based on Detection Tool by Armis
Title source: metasploitExploitation Summary
EIP tracks 1 public exploit for CVE-2019-12258.
PoCs published by Ben Seri, Brent Cook, wvu, including Metasploit module auxiliary/scanner/vxworks/urgent11_check.
AI-analyzed exploit summary This Metasploit module scans for devices vulnerable to CVE-2019-12258 by sending malformed TCP and ICMP packets to detect the presence of VxWorks and IPnet stack. It does not exploit the vulnerability but identifies affected systems.
Description
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
Exploits (1)
This Metasploit module scans for devices vulnerable to CVE-2019-12258 by sending malformed TCP and ICMP packets to detect the presence of VxWorks and IPnet stack. It does not exploit the vulnerability but identifies affected systems.
References (9)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H