← Vulnerability feed

Vulnerability record · CVE-2019-12257 · published 9 August 2019

CVE-2019-12257: VxWorks IPNET DHCP client heap buffer overflow in Offer/ACK parsing

Windriver · Vxworks

Wind River VxWorks 6.6 through 6.9 contains a heap buffer overflow in the IPNET DHCP client (ipdhcpc) while parsing DHCP Offer and ACK messages. Because the DHCP client runs on embedded and industrial devices, a malformed server response can corrupt memory in a component that is normally trusted. The record does not state whether code execution is proven, only that the overflow exists.

8.8 CVSS 3.1 High EPSS 84% · top 0.3% CWE-120 · Classic buffer overflow
8.8CVSS 3.1 base score, v2 5.8
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.8 with no authentication or user interaction and a very high EPSS score, but no KEV listing or confirmed in-the-wild exploitation in the record.

What it is

Wind River VxWorks 6.6 through 6.9 contains a heap buffer overflow in the IPNET DHCP client (ipdhcpc) while parsing DHCP Offer and ACK messages. Because the DHCP client runs on embedded and industrial devices, a malformed server response can corrupt memory in a component that is normally trusted. The record does not state whether code execution is proven, only that the overflow exists.

Impact

An attacker who can deliver a crafted DHCP Offer or ACK can corrupt heap memory in the DHCP client, with the CVSS vector indicating high confidentiality, integrity and availability impact. That implies potential code execution or denial of service on the affected device, though the record does not confirm which outcome is achieved.

Attack surface

The flaw is reached over the adjacent network via DHCP traffic, requiring no authentication and no user interaction per the CVSS vector AV:A/PR:N/UI:N. An attacker must be positioned to answer or spoof DHCP responses to a device running the vulnerable client.

Exploitation

CVE-2019-12257 is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.842 (99.7th percentile), indicating strong predicted exploitation likelihood. Reference tags are only vendor and third-party advisories, with no public exploit or in-the-wild tag supplied.

What to do

  • Apply the Wind River IPNET urgent11 fix or the vendor firmware update for each affected product (VxWorks, SonicOS, Siemens SIPROTEC 5, NetApp E-Series, Belden/Hirschmann/GarrettCom devices).
  • Where patching is not yet possible, disable the DHCP client and use static IP configuration on affected devices.
  • Restrict DHCP to trusted servers and block rogue DHCP responses at the network edge using DHCP snooping or port security.
  • Segment industrial and embedded devices so untrusted hosts cannot reach them at layer 2 and inject DHCP replies.
  • Track vendor advisories (Wind River, Siemens, SonicWall, NetApp, F5) for updated fixed versions.

Detection

  • Monitor for unexpected or duplicate DHCP servers and Offer/ACK responses on segments containing affected devices.
  • Alert on DHCP client crashes, reboots or watchdog resets on VxWorks-based and industrial devices.
  • Use DHCP snooping logs and switch port security events to identify unauthorized DHCP responders.
  • Baseline device behavior and investigate unexplained process restarts or memory faults on affected firmware.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12257 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed9.8CVE-2021-43527Mozilla nss out-of-bounds write vulnerabilityNSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signa…EPSS 18%9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed9.8CVE-2021-33574Gnu glibc use after free vulnerabilityThe mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes ob…EPSS 2.9%9.8CVE-2021-27734Belden hirschmann hios improper authentication vulnerabilityHirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of…EPSS 1.3%9.8CVE-2020-6994Belden hirschmann hios classic buffer overflow vulnerabilityA buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper…EPSS 1.6%9.8CVE-2019-18805Linux kernel integer overflow vulnerabilityAn issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in t…EPSS 3.4%9.8CVE-2019-12262Windriver vxworks vulnerabilityWind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unso…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2019-12257), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.