CVE Vulnerabilities

CVE-2019-12258

Session Fixation

Published: Aug 09, 2019 | Modified: Aug 12, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.

Weakness

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Affected Software

Name Vendor Start Version End Version
Vxworks Windriver 6.5 (including) 6.9.4.12 (excluding)
Vxworks Windriver 7.0 (including) 7.0 (including)

Extended Description

Such a scenario is commonly observed when:

Potential Mitigations

References