sonicwall sonicos Security Vulnerabilities

23 Vulnerabilities
Description

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets? IP options.

Impacted versions: 6.2.7.7, 6.2.7.1, 6.2.7.0

Base Score: 7.5, Severity: HIGH, ID: CVE-2019-12256, Last Modified: 2019-10-10T12:09:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets? IP options.

Impacted versions: *

Base Score: 7.5, Severity: HIGH, ID: CVE-2019-12256, Last Modified: 2019-10-10T12:09:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext data when CBC cipher suites are enabled. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).

Impacted versions: 6.5.1.8, 6.5.3.1, 6.2.7.3, 6.5.2.2, 6.4.0.0, *, 6.0.5.3-86o, 6.5.1.3, 6.2.7.8

Base Score: 5.0, Severity: MEDIUM, ID: CVE-2019-7477, Last Modified: 2019-10-09T23:52:00Z

References

Vendor Advisory

A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivileged user to access advanced routing services. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).

Impacted versions: 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.5.3.1, *, 6.2.7.3, 6.0.5.3-86o, 6.5.1.3, 6.5.2.2

Base Score: 7.5, Severity: HIGH, ID: CVE-2019-7475, Last Modified: 2019-10-09T23:52:00Z

References

Vendor Advisory

A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unstable state by downloading certificate with specific extension. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).

Impacted versions: 6.2.7.3, 6.5.1.3, 6.5.1.8, 6.5.2.2, 6.5.3.1, *, 6.2.7.8, 6.0.5.3-86o, 6.4.0.0

Base Score: 4.0, Severity: MEDIUM, ID: CVE-2019-7474, Last Modified: 2019-10-09T23:52:00Z

References

Vendor Advisory

In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).

Impacted versions: *

Base Score: 2.1, Severity: LOW, ID: CVE-2018-9867, Last Modified: 2019-10-03T00:03:00Z

References

Vendor Advisory Third Party Advisory

Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.

Impacted versions: 6.2.7.1, 6.2.7.7

Base Score: 7.5, Severity: HIGH, ID: CVE-2019-12255, Last Modified: 2019-10-02T15:15:00Z

References

Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.

Impacted versions: *

Base Score: 7.5, Severity: HIGH, ID: CVE-2019-12255, Last Modified: 2019-10-02T15:15:00Z

References

Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.

Impacted versions: *

Base Score: 5.0, Severity: MEDIUM, ID: CVE-2019-12258, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.

Impacted versions: 6.2.7.0, 6.2.7.7, 6.2.7.1

Base Score: 5.0, Severity: MEDIUM, ID: CVE-2019-12258, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

Impacted versions: 6.2.7.0, 6.2.7.1, 6.2.7.7

Base Score: 5.0, Severity: MEDIUM, ID: CVE-2019-12259, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

Impacted versions: *

Base Score: 5.0, Severity: MEDIUM, ID: CVE-2019-12259, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.

Impacted versions: *

Base Score: 5.0, Severity: MEDIUM, ID: CVE-2019-12265, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.

Impacted versions: 6.2.7.1, 6.2.7.7, 6.2.7.0

Base Score: 5.0, Severity: MEDIUM, ID: CVE-2019-12265, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.

Impacted versions: 6.2.7.1, 6.2.7.7

Base Score: 7.5, Severity: HIGH, ID: CVE-2019-12261, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.

Impacted versions: *

Base Score: 7.5, Severity: HIGH, ID: CVE-2019-12260, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.

Impacted versions: 6.2.7.7, 6.2.7.1

Base Score: 7.5, Severity: HIGH, ID: CVE-2019-12260, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.

Impacted versions: *

Base Score: 7.5, Severity: HIGH, ID: CVE-2019-12261, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.

Impacted versions: *

Base Score: 6.8, Severity: MEDIUM, ID: CVE-2019-12263, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.

Impacted versions: 6.2.7.1, 6.2.7.7, 6.2.7.0

Base Score: 6.8, Severity: MEDIUM, ID: CVE-2019-12263, Last Modified: 2019-09-10T13:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.

Impacted versions: *

Base Score: 5.8, Severity: MEDIUM, ID: CVE-2019-12257, Last Modified: 2019-08-16T21:15:00Z

References

Third Party Advisory

Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.

Impacted versions: 6.2.7.7, 6.2.7.1, 6.2.7.0

Base Score: 5.8, Severity: MEDIUM, ID: CVE-2019-12257, Last Modified: 2019-08-16T21:15:00Z

References

Third Party Advisory Third Party Advisory Third Party Advisory Vendor Advisory Issue Tracking Issue Tracking Vendor Advisory

Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter.

Impacted versions: *, 7.5.0.12

Base Score: 4.3, Severity: MEDIUM, ID: CVE-2015-3447, Last Modified: 2018-10-09T19:56:00Z

References

Exploit Exploit Exploit Third Party Advisory Third Party Advisory Third Party Advisory Third Party Advisory Exploit Exploit
Free Home-Networking Courses, tutorials and security checklists

USAGE: Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.