7.8
CVSSv2

CVE-2010-2966

Published: 05/08/2010 Updated: 05/08/2010
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The INCLUDE_SECURITY functionality in Wind River VxWorks 6.x, 5.x, and previous versions uses the LOGIN_USER_NAME and LOGIN_USER_PASSWORD (aka LOGIN_PASSWORD) parameters to create hardcoded credentials, which makes it easier for remote malicious users to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session.

Vulnerable Product Search on Vulmon Subscribe to Product

windriver vxworks

windriver vxworks 5.5

windriver vxworks 6.4

windriver vxworks 5

windriver vxworks 6