Total vulnerabilities in the database
The INCLUDE_SECURITY functionality in Wind River VxWorks 6.x, 5.x, and earlier uses the LOGIN_USER_NAME and LOGIN_USER_PASSWORD (aka LOGIN_PASSWORD) parameters to create hardcoded credentials, which makes it easier for remote attackers to obtain access via a (1) telnet, (2) rlogin, or (3) FTP session.
Software | From | Fixed in |
---|---|---|
windriver / vxworks | 6 | 6.x |
windriver / vxworks | 5 | 5.x |
windriver / vxworks | 6.4 | 6.4.x |
windriver / vxworks | - | 6.8.x |
windriver / vxworks | 5.5 | 5.5.x |