VYPR
Medium severity4.3NVD Advisory· Published May 14, 2024· Updated Apr 15, 2026

CVE-2024-28759

CVE-2024-28759

Description

A crafted network packet causes a buffer overrun in Wind River VxWorks 7 through 23.09, leading to potential denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A crafted network packet causes a buffer overrun in Wind River VxWorks 7 through 23.09, leading to potential denial of service.

Vulnerability

Overview

The vulnerability identified in CVE-2024-28759 involves a buffer overrun that can be triggered by sending a specifically crafted network packet to a system running Wind River VxWorks version 7 through 23.09 [1]. The root cause is a flaw in how the network stack processes incoming data, which fails to properly validate packet boundaries, allowing an overrun condition to occur.

Attack

Vector and Prerequisites

To exploit this vulnerability, an attacker must be able to send a crafted network packet to the target VxWorks device [2]. No authentication is required, and the attack can be performed remotely over the network [1]. The complexity is low, but the attack requires the capability to transmit a specially designed packet to the target system.

Impact

A successful exploit results in a buffer overrun, which can cause the affected device to crash or behave unexpectedly [1]. This primarily leads to a denial of service (DoS) condition, impacting availability of the system. Given VxWorks' use in mission-critical and real-time systems [1], such an outage could have significant operational consequences.

Mitigation

Wind River has provided security updates and guidance for this vulnerability [2]. Users should apply the recommended patches or upgrades to mitigate the risk. The vulnerability has a CVSS v3 base score of 4.3 (Medium severity) [2], and while no public exploitation has been reported, timely patching is advised.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.