Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vxworks | Windriver | 6.5 (including) | 6.9.4.12 (excluding) |
Vxworks | Windriver | 7.0 (including) | 7.0 (including) |
Such a scenario is commonly observed when: