Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2023-40462

Disclosure Date: December 04, 2023
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

The ACEManager
component of ALEOS 4.16 and earlier does not

perform input
sanitization during authentication, which could

potentially result
in a Denial of Service (DoS) condition for

ACEManager without
impairing other router functions. ACEManager

recovers from the
DoS condition by restarting within ten seconds of

becoming
unavailable.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
7.5 High
Impact Score:
3.6
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Additional Info

Technical Analysis