CVE-2010-2967: High severity Windriver Vxworks vulnerability
Published Aug 4, 2010
·Updated
The loginDefaultEncrypt algorithm in loginLib in Wind River VxWorks before 6.9 does not properly support a large set of distinct possible passwords, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session.
Affected Software
5 affected components
Windriver Vxworks=6
Windriver Vxworks=5
Windriver Vxworks=6.4
Windriver Vxworks<=6.8
Windriver Vxworks=5.5
Event History
Aug 4, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2967?
CVE-2010-2967 is considered a medium severity vulnerability.
2
How do I fix CVE-2010-2967?
To fix CVE-2010-2967, users should upgrade to Wind River VxWorks version 6.9 or later.
3
What does CVE-2010-2967 affect?
CVE-2010-2967 affects Wind River VxWorks versions prior to 6.9 and all versions of 5.x.
4
Can CVE-2010-2967 be exploited remotely?
Yes, CVE-2010-2967 allows remote attackers to gain access via telnet, rlogin, or FTP.
5
What is the impact of CVE-2010-2967?
The impact of CVE-2010-2967 is unauthorized access to systems using affected versions of Wind River VxWorks.