CVE-2020-11440: High severity wind river vxworks vulnerability
Published Jul 23, 2020
·Updated
httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.
Affected Software
3 affected components
Windriver Vxworks>=5.5<7.0
Windriver Vxworks=7.0
Windriver Vxworks=7.0-sr0630
Event History
Jul 23, 2020
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
Description
Frequently Asked Questions
1
What is CVE-2020-11440?
CVE-2020-11440 is a vulnerability in the httpRpmFs component in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 that allows an escape from the web root.
2
What is the severity of CVE-2020-11440?
The severity of CVE-2020-11440 is high, with a CVSS score of 7.5.
3
What software is affected by CVE-2020-11440?
Wind River VxWorks versions 5.5 through 7 SR0640, as well as version 7.0 and version 7.0-sr0630, are affected by CVE-2020-11440.
4
How can I fix CVE-2020-11440?
To fix CVE-2020-11440, it is recommended to update to a patched version of Wind River VxWorks.
5
Where can I find more information about CVE-2020-11440?
More information about CVE-2020-11440 can be found on the Wind River website and the official CVE page.