Vulnerability record · CVE-2019-12265 · published 9 August 2019
CVE-2019-12265: VxWorks IPNET IGMPv3 memory leak leaks information
Windriver · Vxworks
Wind River VxWorks 6.5 through 6.9.4 contains a memory leak in the IGMPv3 client component of the IPNET TCP/IP stack, described as an IGMP information leak triggered by an IGMPv3-specific membership report. Because the flaw is reachable over the network without credentials, it matters to any device embedding the affected stack, including products from SonicWall, Siemens, NetApp, Belden and others listed in the advisory references.
Description
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
medium priorityCVSS rates it medium (5.3) with only low confidentiality impact, but the high EPSS score and wide OEM footprint keep it worth prompt patching.
What it is
Wind River VxWorks 6.5 through 6.9.4 contains a memory leak in the IGMPv3 client component of the IPNET TCP/IP stack, described as an IGMP information leak triggered by an IGMPv3-specific membership report. Because the flaw is reachable over the network without credentials, it matters to any device embedding the affected stack, including products from SonicWall, Siemens, NetApp, Belden and others listed in the advisory references.
Impact
An attacker gains limited confidentiality impact, potentially reading small amounts of memory contents exposed through the IGMP handling path. There is no integrity or availability impact recorded in the CVSS vector.
Attack surface
Reached over the network via IGMP traffic, specifically an IGMPv3 membership report; the CVSS vector shows no privileges and no user interaction required. The description does not state whether the attacker must be on the same layer-2 segment or able to send multicast traffic to the target.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.598 (99th percentile), indicating elevated predicted exploitation likelihood. All references are vendor or third-party advisories with no public exploit or PoC tags.
What to do
- Apply the Wind River IPNET urgent11 fix or the vendor firmware update for each affected product (VxWorks, SonicOS, Siemens SIPROTEC 5, NetApp SANtricity, Belden/Hirschmann/GarrettCom devices).
- Track and apply the linked Siemens, SonicWall, NetApp and F5 advisories for the specific product versions in use.
- Restrict IGMP and multicast traffic at network boundaries and on segments where it is not required, since the flaw is triggered by IGMPv3 membership reports.
- Segment or isolate affected embedded and industrial devices so multicast traffic from untrusted hosts cannot reach them.
- Monitor vendor advisories for updated fixed firmware if the device cannot be patched immediately.
Detection
- Monitor for unexpected or malformed IGMPv3 membership reports directed at affected devices, especially from hosts that do not normally send multicast group management traffic.
- Watch device logs and telemetry for memory exhaustion, restarts or instability in embedded devices running the affected IPNET stack.
- Baseline normal IGMP traffic per segment and alert on new sources or unusual group membership report patterns.
- Inventory devices running VxWorks or the listed OEM products to confirm which are exposed to multicast-capable network segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-12265 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-12265), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.