Article 4MBB9 Oh Sh*t's, 11: VxWorks Stars in Today's Security Thriller

Oh Sh*t's, 11: VxWorks Stars in Today's Security Thriller

by
martyb
from SoylentNews on (#4MBB9)

upstart writes:

Submitted via IRC for Carny

Oh sh*t's, 11: VxWorks stars in today's security thriller - hijack bugs discovered in countless gadgets' network code

Wind River has patched 11 security vulnerabilities in VxWorks that can be potentially exploited over networks or the internet to commandeer all sorts of equipment dotted around the planet.

This real-time operating system powers car electronics, factory robots and controllers, aircraft and spacecraft, wireless routers, medical equipment, digital displays, and plenty of other stuff - so if you deploy a vulnerable version of VxWorks, and it is network or internet-connected, you definitely want to check this out.

This set of bugs seemingly primarily affects things like printers and gateways, we must point out.

The vulnerabilities, discovered by security outfit Armis, can be exploited to leak internal device information, crash gadgets, and - in more than half of the flaws - execute malicious code on machines. It is estimated that VxWorks runs on two billion devices as an embedded OS, though Armis reckoned 200 million gizmos are actually potentially affected. Wind River told El Reg it reckons that second figure, as an estimate, is too high.

Read more of this story at SoylentNews.

External Content
Source RSS or Atom Feed
Feed Location https://soylentnews.org/index.rss
Feed Title SoylentNews
Feed Link https://soylentnews.org/
Feed Copyright Copyright 2014, SoylentNews
Reply 0 comments