Description Preview
Wind River VxWorks releases 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 expose a memory leak in the IGMPv3 client component of the IPNET stack. This IPNET security vulnerability facilitates an IGMP information leak through IGMPv3-specific membership reports, with potential impact including memory exhaustion and degraded device availability or exposure of information.
Overview
Wind River VxWorks versions 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 contain a memory leak in the IGMPv3 client portion of the IPNET stack, resulting in an information leak via IGMPv3 membership reports. This vulnerability can lead to memory exhaustion and degraded system availability or inadvertent exposure of information through IGMP traffic.
Remediation
- Apply the vendor-provided patch or firmware update that fixes the IGMPv3/IPNET memory leak (e.g., the Wind River IPNET urgent11 update). Verify patch applicability for your VxWorks version and install it on affected devices.
- If an official patch is not yet available, implement mitigations:
- Disable IGMPv3 or limit IGMPv3 functionality on devices where it is not required.
- Restrict IGMP traffic to trusted network segments and apply strict firewall/ACL rules to control multicast traffic.
- Segment networks to limit exposure of IGMP traffic to impacted devices.
- Monitor memory usage and enable relevant logging to detect unusual IGMP activity or memory growth.
- Validate remediation with testing in a controlled environment and recheck that the patch version is active on all affected systems.
- Maintain an inventory of affected devices and track vendor advisories for new updates or further mitigations.
References
- Wind River Security: IPNET urgent11 advisory https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
- Wind River CVE view: CVE-2019-12265 https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12265
- Wind River security notices https://support2.windriver.com/index.php?page=security-notices
- SonicWall PSIRT: SNWLID-2019-0009 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009
- Siemens SSA-632562.pdf https://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdf
- NetApp Advisory: NTAP-20190802-0001 https://security.netapp.com/advisory/ntap-20190802-0001/
- F5 Article: K41190253 https://support.f5.com/csp/article/K41190253
- Siemens SSA-189842.pdf https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdf
- Siemens SSA-352504.pdf https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdf
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing: Medium
- Health Care & Social AssistanceHealth Care & Social Assistance: Medium
- Public AdministrationPublic Administration: Medium
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Retail TradeRetail Trade: Low
- UtilitiesUtilities: Low
- Transportation & WarehousingTransportation & Warehousing: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- MiningMining: Low
- Accommodation & Food ServicesAccommodation & Food Services: Low
- InformationInformation: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- Educational ServicesEducational Services: Low
- Finance and InsuranceFinance and Insurance: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- ConstructionConstruction: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- Wholesale TradeWholesale Trade: Low