Vulnerability record · CVE-2019-12257 · published 9 August 2019
CVE-2019-12257: VxWorks IPNET DHCP client heap buffer overflow in Offer/ACK parsing
Windriver · Vxworks
Wind River VxWorks 6.6 through 6.9 contains a heap buffer overflow in the IPNET DHCP client (ipdhcpc) while parsing DHCP Offer and ACK messages. Because the DHCP client runs on embedded and industrial devices, a malformed server response can corrupt memory in a component that is normally trusted. The record does not state whether code execution is proven, only that the overflow exists.
Description
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with no authentication or user interaction and a very high EPSS score, but no KEV listing or confirmed in-the-wild exploitation in the record.
What it is
Wind River VxWorks 6.6 through 6.9 contains a heap buffer overflow in the IPNET DHCP client (ipdhcpc) while parsing DHCP Offer and ACK messages. Because the DHCP client runs on embedded and industrial devices, a malformed server response can corrupt memory in a component that is normally trusted. The record does not state whether code execution is proven, only that the overflow exists.
Impact
An attacker who can deliver a crafted DHCP Offer or ACK can corrupt heap memory in the DHCP client, with the CVSS vector indicating high confidentiality, integrity and availability impact. That implies potential code execution or denial of service on the affected device, though the record does not confirm which outcome is achieved.
Attack surface
The flaw is reached over the adjacent network via DHCP traffic, requiring no authentication and no user interaction per the CVSS vector AV:A/PR:N/UI:N. An attacker must be positioned to answer or spoof DHCP responses to a device running the vulnerable client.
Exploitation
CVE-2019-12257 is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.842 (99.7th percentile), indicating strong predicted exploitation likelihood. Reference tags are only vendor and third-party advisories, with no public exploit or in-the-wild tag supplied.
What to do
- Apply the Wind River IPNET urgent11 fix or the vendor firmware update for each affected product (VxWorks, SonicOS, Siemens SIPROTEC 5, NetApp E-Series, Belden/Hirschmann/GarrettCom devices).
- Where patching is not yet possible, disable the DHCP client and use static IP configuration on affected devices.
- Restrict DHCP to trusted servers and block rogue DHCP responses at the network edge using DHCP snooping or port security.
- Segment industrial and embedded devices so untrusted hosts cannot reach them at layer 2 and inject DHCP replies.
- Track vendor advisories (Wind River, Siemens, SonicWall, NetApp, F5) for updated fixed versions.
Detection
- Monitor for unexpected or duplicate DHCP servers and Offer/ACK responses on segments containing affected devices.
- Alert on DHCP client crashes, reboots or watchdog resets on VxWorks-based and industrial devices.
- Use DHCP snooping logs and switch port security events to identify unauthorized DHCP responders.
- Baseline device behavior and investigate unexplained process restarts or memory faults on affected firmware.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-12257 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-12257), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.