SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12259

There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

HIGH 7.5EPSS 15.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 15.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
15.88% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
windriver/vxworks · sonicwall/sonicos · siemens/siprotec 5 firmware · siemens/ruggedcom win7000 firmware · siemens/ruggedcom win7200 firmware · siemens/ruggedcom win7025 firmware · siemens/ruggedcom win7018 firmware · siemens/9410 power meter firmware · siemens/9810 power meter firmware · belden/hirschmann hios · belden/garrettcom magnum dx940e firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.