Description Preview
Wind River VxWorks versions 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 expose an Incorrect Access Control in the IPv4 address assignment performed by the ipdhcpc DHCP client component. This vulnerability could allow bypassing the intended access controls during IPv4 configuration via DHCP, potentially impacting the security of network configuration on affected devices.
Overview
This vulnerability arises from an incorrect access control mechanism in the IPv4 address assignment process within the ipdhcpc DHCP client on Wind River VxWorks. Affected versions include 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7. The issue could allow an attacker to bypass or subvert the intended access restrictions during IPv4 DHCP configuration, which may impact network security and device configuration.
Remediation
- Upgrade to a fixed version or apply the vendor-provided patch for Wind River VxWorks as specified in Wind River advisories for CVE-2019-12264.
- If upgrading is not immediately feasible, disable or restrict the IPv4 DHCP client (ipdhcpc) usage where possible, or configure devices to use static IP addressing to mitigate risk.
- Enforce network segregation and limit DHCP traffic to trusted segments to reduce exposure of affected devices.
- Monitor vendor security advisories and CVE updates, and apply subsequent hotfixes or patches as they become available.
- Validate the remediation by testing IPv4 DHCP behavior in a controlled environment after patching/upgrading.
References
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12264
- https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
- https://support.f5.com/csp/article/K41190253
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdf
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03960en_us
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing: Medium
- Health Care & Social AssistanceHealth Care & Social Assistance: Medium
- Public AdministrationPublic Administration: Medium
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Retail TradeRetail Trade: Low
- UtilitiesUtilities: Low
- Transportation & WarehousingTransportation & Warehousing: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- Educational ServicesEducational Services: Low
- InformationInformation: Low
- MiningMining: Low
- Accommodation & Food ServicesAccommodation & Food Services: Low
- Finance and InsuranceFinance and Insurance: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- Wholesale TradeWholesale Trade: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- ConstructionConstruction: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low

