CVE-2010-2965
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 57.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls, or manage tasks via requests to UDP port 17185, a related issue to CVE-2005-3804.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 57.82% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- rockwellautomation/1756-enbt\/a firmware · windriver/vxworks
- Source
- cve@mitre.org
References
- http://blog.metasploit.com/2010/08/vxworks-vulnerabilities.htmlNot Applicable
- http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=69735Permissions Required
- http://www.kb.cert.org/vuls/id/362332Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86EPFAThird Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86FPQLThird Party Advisory, US Government Resource
- https://support.windriver.com/olsPortal/faces/maintenance/downloadDetails.jspx?contentId=033708Permissions Required
- http://blog.metasploit.com/2010/08/vxworks-vulnerabilities.htmlNot Applicable
- http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=69735Permissions Required
- http://seclists.org/fulldisclosure/2025/Jan/10
- http://www.kb.cert.org/vuls/id/362332Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86EPFAThird Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86FPQLThird Party Advisory, US Government Resource
- https://support.windriver.com/olsPortal/faces/maintenance/downloadDetails.jspx?contentId=033708Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.