VulnerabilityModified
CVE-2019-12259
There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.
HIGH 7.5EPSS 15.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 15.88% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- windriver/vxworks · sonicwall/sonicos · siemens/siprotec 5 firmware · siemens/ruggedcom win7000 firmware · siemens/ruggedcom win7200 firmware · siemens/ruggedcom win7025 firmware · siemens/ruggedcom win7018 firmware · siemens/9410 power meter firmware · siemens/9810 power meter firmware · belden/hirschmann hios · belden/garrettcom magnum dx940e firmware
- Source
- cve@mitre.org
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdfThird Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190802-0001/Third Party Advisory
- https://support.f5.com/csp/article/K41190253Third Party Advisory
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12259Vendor Advisory
- https://support2.windriver.com/index.php?page=security-noticesIssue Tracking, Vendor Advisory
- https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdfThird Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190802-0001/Third Party Advisory
- https://support.f5.com/csp/article/K41190253Third Party Advisory
- https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12259Vendor Advisory
- https://support2.windriver.com/index.php?page=security-noticesIssue Tracking, Vendor Advisory
- https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.