CVE-2022-38767
Published Nov 25, 2022
·Updated
An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure.
Affected Software
8 affected components
Windriver Vxworks>=6.9<6.9.4.12
Windriver Vxworks=6.9.4.12
Windriver Vxworks=6.9.4.12-rolling_cumulative_patch_layer1
Windriver Vxworks=6.9.4.12-rolling_cumulative_patch_layer2
Windriver Vxworks=6.9.4.12-rolling_cumulative_patch_layer3
Windriver Vxworks=6.9.4.12-rolling_cumulative_patch_layer4
Windriver Vxworks=6.9.4.12-rolling_cumulative_patch_layer5
Windriver Vxworks=7.0
Event History
Nov 25, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2022-38767.
2
What is the severity level of CVE-2022-38767?
The severity level of CVE-2022-38767 is high.
3
Which software versions are affected by CVE-2022-38767?
Wind River VxWorks 6.9 and 7 are affected by CVE-2022-38767.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a specifically crafted packet by a Radius server during the IP Radius access procedure.
5
Is there a patch or fix available for CVE-2022-38767?
Please refer to the official Wind River website for available patches or fixes for CVE-2022-38767.