VxWorks contains a flaw that may allow a remote attacker to read and write arbitrary memory on the device. The issue is triggered by leaving the WDB target agent debug service enabled by default.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Solution:
Workaround
Exploit:
Exploit Public
Disclosure:
Vendor Verified
OSVDB:
SCADA
Solution
Currently, there are no known upgrades or patches to correct this vulnerability. It is possible to temporarily work around the flaw by implementing the following workaround: Disable the WDB target agent debug service.