ALEOS
by ALEOS
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46649 | Hig | 0.57 | 8.8 | 0.02 | Feb 10, 2023 | Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device. | ||
| CVE-2019-11862 | Hig | 0.53 | 8.1 | 0.01 | Aug 21, 2020 | The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying. | ||
| CVE-2020-8781 | Hig | 0.51 | 7.8 | 0.00 | Oct 6, 2020 | Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process. | ||
| CVE-2020-8782 | Hig | 0.49 | 7.5 | 0.02 | Oct 6, 2020 | Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution. | ||
| CVE-2019-11847 | Hig | 0.47 | 7.3 | 0.00 | Aug 21, 2020 | An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell. | ||
| CVE-2019-11859 | Med | 0.39 | 6.0 | 0.02 | Aug 21, 2020 | A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root. | ||
| CVE-2019-11858 | Med | 0.37 | 5.7 | 0.01 | Aug 21, 2020 | Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9. | ||
| CVE-2022-46650 | Med | 0.33 | 4.9 | 0.12 | Feb 10, 2023 | Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page. | ||
| CVE-2019-11853 | Low | 0.25 | 3.9 | 0.01 | Aug 21, 2020 | Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4. | ||
| CVE-2019-11856 | Low | 0.22 | 3.3 | 0.01 | Aug 21, 2020 | A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials. |
- risk 0.57cvss 8.8epss 0.02
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
- risk 0.53cvss 8.1epss 0.01
The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.
- risk 0.51cvss 7.8epss 0.00
Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.
- risk 0.49cvss 7.5epss 0.02
Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.
- risk 0.47cvss 7.3epss 0.00
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.
- risk 0.39cvss 6.0epss 0.02
A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.
- risk 0.37cvss 5.7epss 0.01
Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.
- risk 0.33cvss 4.9epss 0.12
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
- risk 0.25cvss 3.9epss 0.01
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
- risk 0.22cvss 3.3epss 0.01
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.