Vulnerabilities
Vulnerable Software
Sierrawireless:  Security Vulnerabilities
A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution
CVSS Score
6.3
EPSS Score
0.0
Published
2020-08-21
An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed via the ACEviewservice, accessible by default on the LAN.
CVSS Score
3.7
EPSS Score
0.0
Published
2020-08-21
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
CVSS Score
3.9
EPSS Score
0.0
Published
2020-08-21
An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.
CVSS Score
8.1
EPSS Score
0.0
Published
2020-08-21
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.
CVSS Score
3.3
EPSS Score
0.0
Published
2020-08-21
Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.
CVSS Score
9.1
EPSS Score
0.0
Published
2020-08-21
Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.
CVSS Score
5.7
EPSS Score
0.0
Published
2020-08-21
A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.
CVSS Score
6.0
EPSS Score
0.0
Published
2020-08-21
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage this vulnerability to execute arbitrary code with system privileges.
CVSS Score
7.8
EPSS Score
0.0
Published
2020-04-15
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVSS Score
7.1
EPSS Score
0.0
Published
2019-10-31


Contact Us

Shodan ® - All rights reserved