PatchSiren

Windriver CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Windriver CVE published 2017-02-07

CVE-2015-7599

CVE-2015-7599 is a high-severity Wind River VxWorks issue in the RPC authentication path. According to the CVE/NVD record, an integer overflow in _authenticate() within svc_auth.c can be reached when the Remote Procedure Call (RPC) protocol is enabled, allowing a remote attacker to crash the device and, in some cases, possibly execute arbitrary code. The published record lists VxWorks versions 5.5 through [truncated]