Skip to content
Threat Feed
high advisory updated

Multiple Vulnerabilities in Wind River VxWorks 7

Multiple vulnerabilities in Wind River VxWorks 7 allow a local attacker to perform denial-of-service attacks, potentially execute arbitrary code, and disclose or manipulate sensitive data.

What's new

  • 1. added coverage for VxWorks Oct 2, 14:21 via bsi

Wind River has identified multiple security vulnerabilities affecting VxWorks 7, a widely used real-time operating system (RTOS) in embedded devices, industrial control systems, and network infrastructure. These vulnerabilities can be exploited by a local attacker to disrupt service availability through denial-of-service (DoS) conditions, execute arbitrary code with elevated privileges, or perform unauthorized disclosure and manipulation of sensitive system data. Given the pervasive use of VxWorks in critical infrastructure and embedded systems, successful exploitation could lead to significant operational disruptions. Defenders should monitor for vendor updates and patches addressing these specific vulnerabilities as documented by Wind River's security advisories.

Impact

Successful exploitation of these vulnerabilities may lead to a complete denial of service for critical embedded systems, unauthorized remote or local code execution, and data corruption or exposure. These risks are particularly acute for organizations operating within critical infrastructure, medical device manufacturing, and industrial automation sectors that rely on VxWorks 7 for operational stability.

Recommendation

Prioritize the identification of devices running VxWorks 7 within the organization's asset inventory. Verify current firmware versions against the official Wind River security updates and apply relevant patches or mitigations provided by the vendor. Ensure that physical and local access controls for devices running VxWorks are strictly enforced to minimize the local access vector identified in this advisory.


Immediate actions

Review internal asset inventory for VxWorks 7 deployments.

IT Operations 72h

Mitigations

Review official Wind River security portal for VxWorks 7 firmware updates.

immediate IT Operations

VxWorks 7 vulnerabilities

Gaps

  • Lack of specific CVE identifiers prevents targeted patch management.