VYPR
Vendor

Sierrawireless

Products
41
CVEs
63
Across products
110
Status
Private

Products

41
View all 41 products →

Recent CVEs

63
View all 63 CVEs →
  • CVE-2018-4063HigKEVMay 6, 2019
    risk 0.71cvss 8.8epss 0.28

    An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can…

  • CVE-2019-11851CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.02

    The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.

  • CVE-2020-11101CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.

  • CVE-2018-10251CriMay 4, 2018
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full…

  • CVE-2017-6044CriJun 30, 2017
    risk 0.64cvss 9.8epss 0.04

    An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to…

  • CVE-2016-5070CriApr 10, 2017
    risk 0.64cvss 9.8epss 0.01

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext.

  • CVE-2016-5069CriApr 10, 2017
    risk 0.64cvss 9.8epss 0.01

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.

  • CVE-2016-5068CriApr 10, 2017
    risk 0.64cvss 9.8epss 0.02

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.

  • CVE-2016-5066CriApr 10, 2017
    risk 0.64cvss 9.8epss 0.02

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user.

  • CVE-2016-5065CriApr 10, 2017
    risk 0.64cvss 9.8epss 0.03

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection.

  • CVE-2019-11857CriAug 21, 2020
    risk 0.59cvss 9.1epss 0.02

    Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.

  • CVE-2018-4073HigMay 6, 2019
    risk 0.59cvss 8.8epss 0.26

    An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The the binary the endpoint /cgi-bin/Embeded_Ace_TLSet_Task.cgi is a very similar endpoint that is designed for use with…

  • CVE-2018-4072HigMay 6, 2019
    risk 0.59cvss 8.8epss 0.27

    An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task.cgi executable is used to change MSCII configuration values within the configuration manager of…

  • CVE-2018-4071HigMay 6, 2019
    risk 0.59cvss 8.8epss 0.19

    An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceTLGet_Task.cgi executable is used to retrieve MSCII configuration values within the configuration manager…

  • CVE-2018-4070HigMay 6, 2019
    risk 0.59cvss 8.8epss 0.18

    An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user…

  • CVE-2018-4061HigMay 6, 2019
    risk 0.59cvss 8.8epss 0.19

    An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution. An attacker can send an…

  • CVE-2017-15043HigMay 4, 2018
    risk 0.58cvss 8.8epss 0.04

    A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full…

  • CVE-2022-46649HigFeb 10, 2023
    risk 0.57cvss 8.8epss 0.02

    Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.

  • CVE-2018-4066HigMay 6, 2019
    risk 0.57cvss 8.8epss 0.02

    An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated…

  • CVE-2017-6042HigJun 30, 2017
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an…