VYPR

ACEManager

by Sierrawireless

CVEs (5)

  • CVE-2022-46649HigFeb 10, 2023
    risk 0.57cvss 8.8epss 0.02

    Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.

  • CVE-2023-40461HigDec 4, 2023
    risk 0.53cvss 8.1epss 0.00

    The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition.

  • CVE-2023-40459HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.02

    The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers…

  • CVE-2023-40460HigDec 4, 2023
    risk 0.46cvss 7.1epss 0.00

    The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the…

  • CVE-2019-11858MedAug 21, 2020
    risk 0.37cvss 5.7epss 0.01

    Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.