CVE-2019-12261: Belden Garrettcom Magnum DX940E Firmware

Critical severity, CVSS 9.8. EPSS: 9% chance of exploitation in the next 30 days.

Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.

Affected products

  • Belden Garrettcom Magnum DX940E Firmware: up to and including 1.0.1_y7
  • Belden Hirschmann Hios: up to and including 07.0.07; up to and including 07.5.01; up to and including 07.2.04; up to and including 05.3.06
  • Netapp E-Series Santricity OS Controller: from 8.00, up to and including 8.40.50.00
  • Oracle Communications Eagle: from 46.6.0, up to and including 46.8.2
  • Siemens Power Meter 9410 Firmware: before 2.2.1 (fixed in 2.2.1)
  • Siemens Power Meter 9810 Firmware: any version
  • Siemens Ruggedcom WIN7000 Firmware: before bs5.2.461.17 (fixed in bs5.2.461.17)
  • Siemens Ruggedcom WIN7018 Firmware: before bs5.2.461.17 (fixed in bs5.2.461.17)
  • Siemens Ruggedcom WIN7025 Firmware: before bs5.2.461.17 (fixed in bs5.2.461.17)
  • Siemens Ruggedcom WIN7200 Firmware: before bs5.2.461.17 (fixed in bs5.2.461.17)
  • Siemens Siprotec 5 Firmware: before 7.59 (fixed in 7.59); before 7.91 (fixed in 7.91)
  • SonicWall SonicOS: from 5.9.0.0, up to and including 5.9.0.7; from 5.9.1.0., up to and including 5.9.1.12; from 6.2.0.0, up to and including 6.2.3.1; from 6.2.4.0, up to and including 6.2.4.3; from 6.2.5.0, up to and including 6.2.5.3; from 6.2.6.0, up to and including 6.2.6.1; …
  • Windriver Vxworks: from 6.5, before 6.9.4.12 (fixed in 6.9.4.12); version 7.0 only

Published 2019-08-09. Last modified 2026-06-17.