← Vulnerability feed

Vulnerability record · CVE-2019-12259 · published 9 August 2019

CVE-2019-12259: Windriver vxworks null pointer dereference vulnerability

Windriver · Vxworks

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

7.5 CVSS 3.1 High EPSS 16% · top 3.2% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score, v2 5.0
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdf Third Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190802-0001/ Third Party Advisory
https://support.f5.com/csp/article/K41190253 Third Party Advisory
https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12259 Vendor Advisory
https://support2.windriver.com/index.php?page=security-notices Issue TrackingVendor Advisory
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/ Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-189842.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-352504.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdf Third Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0009 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190802-0001/ Third Party Advisory
https://support.f5.com/csp/article/K41190253 Third Party Advisory
https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-12259 Vendor Advisory
https://support2.windriver.com/index.php?page=security-notices Issue TrackingVendor Advisory
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/ Vendor Advisory

Track CVE-2019-12259 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27734Belden hirschmann hios improper authentication vulnerabilityHirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of…EPSS 1.3%9.8CVE-2020-6994Belden hirschmann hios classic buffer overflow vulnerabilityA buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper…EPSS 1.6%9.8CVE-2019-12262Windriver vxworks vulnerabilityWind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unso…EPSS 4.1%9.8CVE-2019-12260Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer…EPSS 23%9.8CVE-2019-12261Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urg…EPSS 9.0%9.8CVE-2019-12255VxWorks IPNET TCP urgent pointer integer underflow buffer overflowWind River VxWorks contains a buffer overflow in the TCP component of its IPNET network stack, triggered by a TCP Urgent Pointer value of 0 that caus…EPSS 75%analysed9.8CVE-2019-12256Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing o…EPSS 27%8.8CVE-2019-12257VxWorks IPNET DHCP client heap buffer overflow in Offer/ACK parsingWind River VxWorks 6.6 through 6.9 contains a heap buffer overflow in the IPNET DHCP client (ipdhcpc) while parsing DHCP Offer and ACK messages. Beca…EPSS 84%analysed

Source: NIST National Vulnerability Database (record CVE-2019-12259), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.