CVE-2010-2966: High severity wind river vxworks vulnerability
The INCLUDESECURITY functionality in Wind River VxWorks 6.x, 5.x, and earlier uses the LOGINUSERNAME and LOGINUSERPASSWORD (aka LOGINPASSWORD) parameters to create hardcoded credentials, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2966?
CVE-2010-2966 is classified as a high severity vulnerability due to its potential to allow unauthorized remote access.
How do I fix CVE-2010-2966?
To fix CVE-2010-2966, it is recommended to upgrade to a patched version of Wind River VxWorks that eliminates the use of hardcoded credentials.
What types of systems are affected by CVE-2010-2966?
CVE-2010-2966 affects Wind River VxWorks versions 5.x and 6.x.
What kind of attacks can exploit CVE-2010-2966?
CVE-2010-2966 can be exploited through telnet, rlogin, or FTP sessions.
Is CVE-2010-2966 related to default credentials?
Yes, CVE-2010-2966 involves hardcoded credentials which can be exploited as default credentials.