CVE-2025-26500 Details
Description
: Uncontrolled Resource Consumption vulnerability in Wind River Systems VxWorks 7 on VxWorks allows Excessive Allocation. Specifically crafted USB packets may lead to the system becoming unavailable This issue affects VxWorks 7: from 22.06 through 24.03.
A vulnerability allowing uncontrolled resource consumption has been identified in Wind River Systems VxWorks 7, specifically in versions 22.06 prior to 24.03. This vulnerability allows excessive allocation of resources, where specially crafted USB packets can lead to the system becoming unavailable.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 21, 2025CISA-ADP
Assessed Mar 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2025-26500 | WindRiver | AdvisoryPermission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | WindRiver |
Affected Products
| Product | Versions |
|---|---|
| Wind River VxWorks 7 | >= 22.06, <= 24.03 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WindRiver |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 21, 2025 | New CVE Received | WindRiver |
Volerion