CVE-2010-2966
05.08.2010, 13:22
The INCLUDE_SECURITY functionality in Wind River VxWorks 6.x, 5.x, and earlier uses the LOGIN_USER_NAME and LOGIN_USER_PASSWORD (aka LOGIN_PASSWORD) parameters to create hardcoded credentials, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session.Enginsight
Vendor | Product | Version |
---|---|---|
windriver | vxworks | 𝑥 ≤ 6.8 |
windriver | vxworks | 5.5 |
windriver | vxworks | 6.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration