Urgent/11 VxWorks RTOS Vulnerabilities
Security researchers have disclosed eleven vulnerabilities, collectively named Urgent/11, affecting Wind River's VxWorks real-time operating system (RTOS).
Summary
Security researchers have disclosed eleven vulnerabilities, collectively named Urgent/11, affecting Wind River's VxWorks real-time operating system (RTOS).
Threat details
They claim that an authenticated remote attacker could exploit these vulnerabilities to gain control of an affected system or cause a denial-of-service (DoS) condition.
VxWorks is a widely used RTOS deployed primarily in industrial control systems across numerous sectors including communications, energy, healthcare, and manufacturing.
The Urgent/11 vulnerabilities affect VxWorks default TCP/IP network stack, known as IPnet. Each vulnerability affects a different component of this stack, but can be combined to enable remote code execution, leak sensitive information, create logic flaws, or cause a DoS condition.
For further information:
- Wind River TCP/IP Network Stack (IPnet, Urgent/11) Security Notification
- ICS-CERT Advisory ICSA-19-211-01
- Armis URGENT/11 white paper (Seri, et al. 2019)
- CVE-2019-12255
- CVE-2019-12256
- CVE-2019-12257
- CVE-2019-12258
- CVE-2019-12259
- CVE-2019-12260
- CVE-2019-12261
- CVE-2019-12262
- CVE-2019-12263
- CVE-2019-12264
- CVE-2019-12265
Remediation steps
| Type | Step |
|---|---|
|
Affected organisations are encouraged to review Wind River's security advisory and IPnet support page (please note that this page requires logging in), and apply the necessary updates. |
Last edited: 14 February 2020 2:43 pm