Lucene search

K
cve[email protected]CVE-2019-12265
HistoryAug 09, 2019 - 7:15 p.m.

CVE-2019-12265

2019-08-0919:15:11
CWE-401
web.nvd.nist.gov
124
2
wind river
vxworks
memory leak
ipnet
security
vulnerability
igmp
igmpv3
information leak
nvd
cve-2019-12265

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

7 High

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.4%

Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.

Affected configurations

NVD
Node
windrivervxworksRange6.56.9.4.12
OR
windrivervxworksMatch7.0-
Node
sonicwallsonicosRange5.9.0.05.9.0.7
OR
sonicwallsonicosRange5.9.1.0.5.9.1.12
OR
sonicwallsonicosRange6.2.0.06.2.3.1
OR
sonicwallsonicosRange6.2.4.06.2.4.3
OR
sonicwallsonicosRange6.2.5.06.2.5.3
OR
sonicwallsonicosRange6.2.6.06.2.6.1
OR
sonicwallsonicosRange6.2.7.06.2.7.4
OR
sonicwallsonicosRange6.2.9.06.2.9.2
OR
sonicwallsonicosRange6.5.0.06.5.0.3
OR
sonicwallsonicosRange6.5.1.06.5.1.4
OR
sonicwallsonicosRange6.5.2.06.5.2.3
OR
sonicwallsonicosRange6.5.3.06.5.3.3
OR
sonicwallsonicosRange6.5.4.0.6.5.4.3
OR
sonicwallsonicosMatch6.2.7.0
OR
sonicwallsonicosMatch6.2.7.1
OR
sonicwallsonicosMatch6.2.7.7
Node
siemenssiprotec_5_firmwareRange<7.91
AND
siemenssiprotec_5Match-
Node
siemenssiprotec_5_firmwareRange<7.59
AND
siemenssiprotec_5Match-
Node
siemenssiprotec_5_firmwareRange<7.91
AND
siemenssiprotec_5Match-
Node
netappe-series_santricity_os_controllerRange8.008.40.50.00
Node
siemenspower_meter_9410_firmwareRange<2.2.1
AND
siemenspower_meter_9410Match-
Node
siemenspower_meter_9810_firmware
AND
siemenspower_meter_9810Match-
Node
siemensruggedcom_win7000_firmwareRange<bs5.2.461.17
AND
siemensruggedcom_win7000Match-
Node
siemensruggedcom_win7018_firmwareRange<bs5.2.461.17
AND
siemensruggedcom_win7018Match-
Node
siemensruggedcom_win7025_firmwareRange<bs5.2.461.17
AND
siemensruggedcom_win7025Match-
Node
siemensruggedcom_win7200_firmwareRange<bs5.2.461.17
AND
siemensruggedcom_win7200Match-
Node
beldenhirschmann_hiosRange07.0.07
AND
beldenhirschmann_ees20Match-
OR
beldenhirschmann_ees25Match-
OR
beldenhirschmann_eesx20Match-
OR
beldenhirschmann_eesx30Match-
OR
beldenhirschmann_grs1020Match-
OR
beldenhirschmann_grs1030Match-
OR
beldenhirschmann_grs1042Match-
OR
beldenhirschmann_grs1120Match-
OR
beldenhirschmann_grs1130Match-
OR
beldenhirschmann_grs1142Match-
OR
beldenhirschmann_msp30Match-
OR
beldenhirschmann_msp32Match-
OR
beldenhirschmann_rail_switch_power_liteMatch-
OR
beldenhirschmann_rail_switch_power_smartMatch-
OR
beldenhirschmann_red25Match-
OR
beldenhirschmann_rsp20Match-
OR
beldenhirschmann_rsp25Match-
OR
beldenhirschmann_rsp30Match-
OR
beldenhirschmann_rsp35Match-
OR
beldenhirschmann_rspe30Match-
OR
beldenhirschmann_rspe32Match-
OR
beldenhirschmann_rspe35Match-
OR
beldenhirschmann_rspe37Match-
Node
beldenhirschmann_hiosRange07.5.01
AND
beldenhirschmann_msp40Match-
OR
beldenhirschmann_octopus_os3Match-
Node
beldenhirschmann_hiosRange07.2.04
AND
beldenhirschmann_dragon_mach4000Match-
OR
beldenhirschmann_dragon_mach4500Match-
Node
beldenhirschmann_hiosRange05.3.06
AND
beldenhirschmann_eagle_oneMatch-
OR
beldenhirschmann_eagle20Match-
OR
beldenhirschmann_eagle30Match-
Node
beldengarrettcom_magnum_dx940e_firmwareRange1.0.1_y7
AND
beldengarrettcom_magnum_dx940eMatch-

Social References

More

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

7 High

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.4%