High severity7.5NVD Advisory· Published Dec 25, 2023· Updated Jun 17, 2026
CVE-2023-38321
CVE-2023-38321
Description
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5<4.17.0.12+ 1 more
- (no CPE)range: <4.17.0.12
- cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:*range: <4.17.0.12
- osv-coords2 versionspkg:deb/ubuntu/[email protected]+dfsg-1build2?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]+dfsg-1build2?arch=source&distro=noble
>= 0+ 1 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.