First published: Wed Aug 04 2010(Updated: )
The FTP daemon in Wind River VxWorks does not close the TCP connection after a number of failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wind River VxWorks | <=6.8 | |
Wind River VxWorks | =5 | |
Wind River VxWorks | =5.5 | |
Wind River VxWorks | =6 | |
Wind River VxWorks | =6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2968 is considered a medium severity vulnerability due to its potential for abuse in brute-force attacks.
To fix CVE-2010-2968, ensure that the FTP daemon is configured to limit the number of failed login attempts and properly close TCP connections.
CVE-2010-2968 affects Wind River VxWorks versions 5.0 to 6.8.
The vulnerability in CVE-2010-2968 stems from the FTP daemon not terminating TCP connections after multiple failed login attempts.
Organizations using affected versions of Wind River VxWorks for their systems might be impacted by CVE-2010-2968.