Skip to main content

Urgent/11 VxWorks RTOS Vulnerabilities

Security researchers have disclosed eleven vulnerabilities, collectively named Urgent/11, affecting Wind River's VxWorks real-time operating system (RTOS).

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security researchers have disclosed eleven vulnerabilities, collectively named Urgent/11, affecting Wind River's VxWorks real-time operating system (RTOS).


Threat details

They claim that an authenticated remote attacker could exploit these vulnerabilities to gain control of an affected system or cause a denial-of-service (DoS) condition.

VxWorks is a widely used RTOS deployed primarily in industrial control systems across numerous sectors including communications, energy, healthcare, and manufacturing.

The Urgent/11 vulnerabilities affect VxWorks default TCP/IP network stack, known as IPnet. Each vulnerability affects a different component of this stack, but can be combined to enable remote code execution, leak sensitive information, create logic flaws, or cause a DoS condition.

For further information:


Remediation steps

Type Step

Affected organisations are encouraged to review Wind River's security advisory and IPnet support page (please note that this page requires logging in), and apply the necessary updates.


Last edited: 14 February 2020 2:43 pm