VYPR

Vxworks

by Windriver

CVEs (43)

  • CVE-2010-2968Aug 5, 2010
    risk 0.00cvss —epss 0.01

    The FTP daemon in Wind River VxWorks does not close the TCP connection after a number of failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

  • CVE-2010-2967Aug 5, 2010
    risk 0.00cvss —epss 0.02

    The loginDefaultEncrypt algorithm in loginLib in Wind River VxWorks before 6.9 does not properly support a large set of distinct possible passwords, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session.

  • CVE-2010-2966Aug 5, 2010
    risk 0.00cvss —epss 0.02

    The INCLUDE_SECURITY functionality in Wind River VxWorks 6.x, 5.x, and earlier uses the LOGIN_USER_NAME and LOGIN_USER_PASSWORD (aka LOGIN_PASSWORD) parameters to create hardcoded credentials, which makes it easier for remote attackers to obtain access via a (1) telnet, (2)…

Page 3 of 3