VYPR

Aleos

by Sierrawireless

CVEs (32)

  • CVE-2023-40460HigDec 4, 2023
    risk 0.46cvss 7.1epss 0.00

    The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the…

  • CVE-2019-11850MedAug 21, 2020
    risk 0.41cvss 6.3epss 0.00

    A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution

  • CVE-2019-11849MedAug 21, 2020
    risk 0.41cvss 6.3epss 0.00

    A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code execution.

  • CVE-2019-11859MedAug 21, 2020
    risk 0.39cvss 6.0epss 0.02

    A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.

  • CVE-2019-11858MedAug 21, 2020
    risk 0.37cvss 5.7epss 0.01

    Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

  • CVE-2022-46650MedFeb 10, 2023
    risk 0.33cvss 4.9epss 0.12

    Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.

  • CVE-2015-6479MedApr 21, 2016
    risk 0.28cvss 4.3epss 0.02

    ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspecified vectors.

  • CVE-2019-11848MedAug 21, 2020
    risk 0.27cvss 4.1epss 0.01

    An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.

  • CVE-2019-11853LowAug 21, 2020
    risk 0.25cvss 3.9epss 0.01

    Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.

  • CVE-2019-11852LowAug 21, 2020
    risk 0.24cvss 3.7epss 0.01

    An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed via the ACEviewservice, accessible by default on the LAN.

  • CVE-2019-11856LowAug 21, 2020
    risk 0.22cvss 3.3epss 0.01

    A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.

  • CVE-2015-2897Aug 8, 2015
    risk 0.00cvss epss 0.02

    Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session.

Page 2 of 2