Vulnerabilities > Windriver > Vxworks > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-08-05 | CVE-2010-2968 | Permissions, Privileges, and Access Controls vulnerability in Windriver Vxworks The FTP daemon in Wind River VxWorks does not close the TCP connection after a number of failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack. | 7.8 |
2010-08-05 | CVE-2010-2967 | Cryptographic Issues vulnerability in Windriver Vxworks The loginDefaultEncrypt algorithm in loginLib in Wind River VxWorks before 6.9 does not properly support a large set of distinct possible passwords, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session. | 7.8 |
2010-08-05 | CVE-2010-2966 | Credentials Management vulnerability in Windriver Vxworks The INCLUDE_SECURITY functionality in Wind River VxWorks 6.x, 5.x, and earlier uses the LOGIN_USER_NAME and LOGIN_USER_PASSWORD (aka LOGIN_PASSWORD) parameters to create hardcoded credentials, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session. | 7.8 |