VxWorks Debugging Service Security-Bypass Vulnerability
BID:42158
Info
VxWorks Debugging Service Security-Bypass Vulnerability
| Bugtraq ID: | 42158 |
| Class: | Design Error |
| CVE: |
CVE-2010-2965 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2010 12:00AM |
| Updated: | Mar 19 2015 08:47AM |
| Credit: | HD Moore |
| Vulnerable: |
Xerox Phaser 3635MFP 0 Wind River Systems VxWorks 0 Proxim Oronoco AP600 2.5.5(1070) Proxim Oronoco AP600 2.5.3(914) Proxim Oronoco AP600 2.5.2(894) Proxim Oronoco AP600 2.4.5(758) Proxim Oronoco AP600 2.4.11(821) Proxim Oronoco AP600 2.2.0(460) Proxim Oronoco AP600 2.1.1(403) Proxim Oronoco AP600 Paradyne GranDSLAM 4200 Nortel Networks WLAN Access Point 2220 Nortel Networks Passport 1100/1150/1200/1250 Nortel Networks Optical Trouble Ticketing 0 Kathrein CMTS038-007 CMTS2.6.0 Kathrein CMTS038-007 CMTS2.17.0 Kathrein CMTS038-007 CMTS2.14.0 Kathrein CMTS038-007 CMTS2.11.0 Guangzhou GaoKe Co MG6000 VoIP Gateway 0 Foundry Networks EdgeIron 4802F 1.4.8 Foundry Networks EdgeIron 4802F 1.3.7 Foundry Networks EdgeIron 4802F 0 Cisco ONS 15454SDH 0 Cisco ONS 15454 0 Cisco IP Phone 7920 ARRIS Cadant C3 CMTS 0 Alcatel-Lucent OmniSwitch 5.1.5.245.R04 |
| Not Vulnerable: | |
Discussion
VxWorks Debugging Service Security-Bypass Vulnerability
VxWorks is prone to a remote security-bypass vulnerability.
Successful exploits will allow remote attackers to perform debugging tasks on the vulnerable device.
The issue affects multiple products from multiple vendors that ship with the VxWorks operating system.
NOTE: This issue was previously covered in BID 42114 (VxWorks Multiple Security Vulnerabilities) but has been separated into its own record to better document it.
VxWorks is prone to a remote security-bypass vulnerability.
Successful exploits will allow remote attackers to perform debugging tasks on the vulnerable device.
The issue affects multiple products from multiple vendors that ship with the VxWorks operating system.
NOTE: This issue was previously covered in BID 42114 (VxWorks Multiple Security Vulnerabilities) but has been separated into its own record to better document it.
Exploit / POC
VxWorks Debugging Service Security-Bypass Vulnerability
Attackers can exploit this issue using readily available tools. A Metasploit exploit module that exploits this issue is also available.
Attackers can exploit this issue using readily available tools. A Metasploit exploit module that exploits this issue is also available.
Solution / Fix
VxWorks Debugging Service Security-Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
VxWorks Debugging Service Security-Bypass Vulnerability
References:
References:
- SCADAPack 330, SCADAPack 334, SCADAPack 350, and SCADAPack 357 Firmware (Schneider Electric)
- Shiny Old VxWorks Vulnerabilities (Metasploit)
- Wind River Homepage (Wind River)
- [R7-0034] VxWorks WDB Agent Debug Service Exposure (HD Moore
) - Vulnerability Note VU#362332 Wind River Systems VxWorks debug service enabled by (US-CERT)