VYPR

Vendor CVEs

Sierrawireless

All CVEs

63 total · sorted by risk
  • CVE-2019-11858MedAug 21, 2020
    risk 0.37cvss 5.7epss 0.01

    Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

  • CVE-2018-4068MedMay 6, 2019
    risk 0.35cvss 5.3epss 0.11

    An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request can result in disclosure of the default configuration for the device. An attacker can send an unauthenticated HTTP request to…

  • CVE-2023-31280MedDec 21, 2024
    risk 0.34cvss 5.3epss 0.00

    An AirVantage online Warranty Checker tool vulnerability could allow an attacker to perform bulk enumeration of IMEI and Serial Numbers pairs. The AirVantage Warranty Checker is updated to no longer return the IMEI and Serial Number in addition to the warranty status when the…

  • CVE-2022-46650MedFeb 10, 2023
    risk 0.33cvss 4.9epss 0.12

    Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.

  • CVE-2015-6479MedApr 21, 2016
    risk 0.28cvss 4.3epss 0.02

    ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspecified vectors.

  • CVE-2019-11848MedAug 21, 2020
    risk 0.27cvss 4.1epss 0.01

    An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.

  • CVE-2019-11853LowAug 21, 2020
    risk 0.25cvss 3.9epss 0.01

    Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.

  • CVE-2019-11852LowAug 21, 2020
    risk 0.24cvss 3.7epss 0.01

    An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed via the ACEviewservice, accessible by default on the LAN.

  • CVE-2019-11856LowAug 21, 2020
    risk 0.22cvss 3.3epss 0.01

    A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.

  • CVE-2015-2897Aug 8, 2015
    risk 0.00cvss epss 0.02

    Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session.

  • CVE-2015-2054Feb 23, 2015
    risk 0.00cvss epss 0.01

    CRLF injection vulnerability in export.cfg in the web-based administrative console for Sierra Wireless AirCard 760S, 762S, and 763S allows remote attackers to inject arbitrary headers via CRLF sequences in the save parameter.

  • CVE-2013-2820Jan 15, 2014
    risk 0.00cvss epss 0.04

    The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.

  • CVE-2013-2819Jan 15, 2014
    risk 0.00cvss epss 0.02

    The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) update or (2) reprogramming action.

Page 2 of 2