Show filters
66 Total Results
Displaying 11-20 of 66
Sort by:
Attacker Value
Unknown

CVE-2023-40459

Disclosure Date: December 04, 2023 (last updated December 09, 2023)
The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
Attacker Value
Unknown

CVE-2023-40458

Disclosure Date: November 29, 2023 (last updated December 05, 2023)
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device.
Attacker Value
Unknown

CVE-2022-46650

Disclosure Date: February 10, 2023 (last updated October 08, 2023)
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
Attacker Value
Unknown

CVE-2022-46649

Disclosure Date: February 10, 2023 (last updated October 08, 2023)
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
Attacker Value
Unknown

CVE-2019-11851

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.
Attacker Value
Unknown

CVE-2019-13988

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).
Attacker Value
Unknown

CVE-2020-11101

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.
Attacker Value
Unknown

CVE-2020-8781

Disclosure Date: October 06, 2020 (last updated November 28, 2024)
Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.
Attacker Value
Unknown

CVE-2020-8782

Disclosure Date: September 17, 2020 (last updated November 28, 2024)
Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.
Attacker Value
Unknown

CVE-2019-11855

Disclosure Date: August 21, 2020 (last updated November 28, 2024)
An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.