Wind River VXWorks TCP predictable Vulnerability (CVE-2015-3963)
Wind River VXWorks TCP predictable Vulnerability (CVE-2015-3963)
Release date:
Updated on:
Affected Systems:
Wind River Systems VxWorks 7.x
Wind River Systems VxWorks 6.x
Description:
CVE (CAN) ID: CVE-2015-3963
VxWorks is a real-time operating system widely used on ICS-related devices.
The VxWorks software generates predictable initial TCP sequence numbers. Attackers can predict the numbers based on the previous values to fool or interrupt TCP connections.
<* Source: Raheem Beyah
David Formby
San Shin Jung
Link: https://ics-cert.us-cert.gov/advisories/ICSA-15-169-01
*>
Suggestion:
Vendor patch:
Wind River Systems
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.schneider-electric.com/ww/en/download/document/SEVD-2015-162-01
This article permanently updates the link address: