logo

Critical Flaws in VxWorks affect 200 Million Connected Things

ID: 01480370-c5e5-53e0-a1be-a3d6944ddbc5

STIX ID: report--01480370-c5e5-53e0-a1be-a3d6944ddbc5

Feed Name: Security Ledger

Threat Score
80/100

Date Published: 2019-07-29

Date Updated: 2026-05-05

Author: Paul Roberts

...
...

Armis disclosed 11 critical vulnerabilities (Urgent/11) in the VxWorks TCP/IP stack affecting VxWorks 6.5 and later—including six remote code execution flaws—that could enable remote takeover of hundreds of millions of embedded devices (industrial, medical, networking, printers, VOIP). Wind River released patches, but remediation depends on OEM firmware updates; several legacy TCP/IP features (e.g., Urgent Pointer, source routing) are the root cause and some vulnerable devices may remain unpatched for months.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.