← Back to home
ICSA-13-091-01  ·  Published 2025-06-06  ·  View on CISA ICS-CERT ↗

Wind River VxWorks SSH and Web Server and General Electric D20MX

CVSS 9.8 CRITICAL

Remediations

  • According to Wind River, software patches for these vulnerabilities are available for all affected VxWorks versions. Users interested in obtaining these patches should contact Wind River technical support for assistance. (http://windriver.com/support/ )
  • GE reports the vulnerabilities do not impact Version 1.7 or newer. To upgrade a D20MX to Version 1.8, users should follow the upgrade procedures: "TN0110 D20MX v1.8+ Upgrade Procedure" or "TN0111 D20MX v1.8+ Upgrade over Serial Procedure"
  • These are available for download from the tech support website: (http://sc.ge.com/*SASTechSupport) > Substation Automation > D20MX > Firmware v1.80 > Documentation.

Affected Vendors

Wind River; GE

Affected Products (3)

Wind River; GE · VxWorks >=5.5|<=6.9
Wind River; GE · VxWorks >=6.5|<=6.9
Wind River; GE · GE D20MX >=v1.0|<=1.6.2

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more