CVE-2013-0714: Input Validation
Published Mar 20, 2013
·Updated
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of service (daemon hang) via a crafted public-key authentication request.
Affected Software
5 affected components
Windriver Vxworks=6.5
Windriver Vxworks=6.6
Windriver Vxworks=6.7
Windriver Vxworks=6.8
Windriver Vxworks=6.9
Event History
Mar 20, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0714?
CVE-2013-0714 is classified as a critical vulnerability allowing remote code execution and denial of service.
2
How do I fix CVE-2013-0714?
To mitigate CVE-2013-0714, upgrade Wind River VxWorks to a version that does not contain the vulnerability.
3
What versions of Wind River VxWorks are affected by CVE-2013-0714?
CVE-2013-0714 affects Wind River VxWorks versions 6.5 through 6.9.
4
Can CVE-2013-0714 be exploited remotely?
Yes, CVE-2013-0714 can be exploited remotely through a crafted public-key authentication request.
5
What impact does CVE-2013-0714 have on systems?
CVE-2013-0714 can cause arbitrary code execution or hang the daemon, leading to denial of service.