Forum Discussion
Eleven vulnerabilities, including RCEs, denials of service,...
Eleven vulnerabilities, including RCEs, denials of service, information leaks and logical flaws, were recently disclosed, impacting the RTOS VxWorks
The Armis Research Team has released an advisory for URGENT/11, which contains six critical RCE and five additional vulnerabilities in VxWorks, a Real-Time Operating System (RTOS) found in over 2 billion devices, including critical industrial, medical and enterprise hardware. Wind River, the maintainer of VxWorks, released patches on July 19 for all 11 of the vulnerabilities.
A list of plugins to identify these vulnerabilities will appear here as they’re released. Please note that vulnerability detection plugin creation also relies on vendor support for any given device. We encourage organizations to examine the plugin output section of our informational detection plugins in their scan results to identify vulnerable systems in addition to scanning with direct vulnerability detection plugins.
For additional analysis and information, please see our blog.
1 Reply
Great news for VxWorks.