CyberICT

CVE-2010-2965

Rockwellautomation · Published August 5, 2010

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls, or manage tasks via requests to UDP port 17185, a related issue to CVE-2005-3804.

Affected Products

  • 1756 Enbt\/a Firmware
  • Vxworks <= 6.9.4.12

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H