CVE-2015-7599: Windriver Vxworks
High severity, CVSS 8.1. EPSS: 5.9% chance of exploitation in the next 30 days.
Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a username and password.
Affected products
- Windriver Vxworks: up to and including 6.9.4.1; version 5.5 only; version 6.4 only; version 6.7 only; version 6.8 only; version 6.9 only
Published 2017-02-07. Last modified 2026-06-17.