This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.
The remote VxWorks device is potentially affected by several
According to its self-reported version, the remote VxWorks device is
version 5.5 through 6.9. It therefore is potentially affected by the
following vulnerabilities :
- An attacker can cause SSH access to be unavailable
until the next reboot with a specially crafted
requests. (CVE-2013-0711 / CVE-2013-0712 /
- An attacker can cause the server to hang and SSH access
to be unavailable until the next reboot by sending a
specially crafted packet for a public key
authentication request. Arbitrary code execution is
also a possibility. (CVE-2013-0714)
- An attacker able to login to a CLI session can cause
the current CLI session to crash. (CVE-2013-0715)
- An attacker able to access the VxWorks Web Server can
cause the server to crash using a specially crafted
Note that the Web Server and CLI vulnerabilities affect VxWorks 5.5
through 6.9 while the SSH vulnerabilities affect only versions 6.5
Note that Nessus has not checked for the presence of the patch so
this finding may be a false positive.
See also :
Contact the device vendor for the appropriate patch.
Risk factor :
Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 8.3
Public Exploit Available : true
Nessus Plugin ID: 69864 ()
Bugtraq ID: 586385853958640586415864258643
CVE ID: CVE-2013-0711CVE-2013-0712CVE-2013-0713CVE-2013-0714CVE-2013-0715CVE-2013-0716
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.