Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-38321 OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer der… Aleos 4.17.0.12+ Fix from $1,9502023-12-25 MEDIUM 6.8 CVE-2023-40464 Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items coul… Aleos after 4.16.0 Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-40465 Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area netwo… Aleos after 4.16.0 Fix from $1,6002023-12-04 HIGH 7.2 CVE-2023-40463 When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the … Aleos after 4.16.0 Fix from $1,9502023-12-04 MEDIUM 5.4 CVE-2023-40460 The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authentica… Aleos after 4.16.0 Fix from $1,6002023-12-04 HIGH 7.5 CVE-2023-40459 The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially resu… Aleos after 4.16.0 Fix from $1,9502023-12-04 HIGH 7.5 CVE-2023-40458 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigg… Aleos after 4.16.2 Fix from $1,9502023-11-29 HIGH 8.8 CVE-2022-46649 Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell comman… Aleos after 4.16.0 Fix from $1,9502023-02-10 CRITICAL 9.8 CVE-2019-11851 The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote att… Aleos 4.4.9 / 4.9.5+ Fix from $2,3002022-12-26 MEDIUM 6.5 CVE-2019-13988 Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing). Mgos 3.15.2 / 4.3+ Fix from $1,6002022-12-26 CRITICAL 9.8 CVE-2020-11101 Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with a… Airlink Mobility Manager 2.17+ Fix from $2,3002022-12-26 CRITICAL 9.8 CVE-2020-8782 Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution. Aleos 4.4.9 / 4.9.5+ Fix from $2,3002020-10-06 HIGH 7.8 CVE-2020-8781 Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process. Aleos 4.14.0+ Fix from $1,9502020-10-06 HIGH 8.4 CVE-2019-11862 The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying. Aleos 4.4.9 / 4.9.5+ Fix from $1,9502020-08-21 CRITICAL 9.8 CVE-2019-11855 An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9. Aleos 4.4.9 / 4.9.5+ Fix from $2,3002020-08-21 CRITICAL 9.1 CVE-2019-11852 An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed v… Aleos 4.4.9 / 4.9.5+ Fix from $2,3002020-08-21 HIGH 8.8 CVE-2019-11859 A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root. Aleos after 4.12.0 Fix from $1,9502020-08-21 HIGH 7.8 CVE-2019-11847 An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the co… Aleos 4.4.9 / 4.9.4+ Fix from $1,9502020-08-21 HIGH 7.2 CVE-2019-11848 An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain use… Aleos 4.4.9 / 4.9.5+ Fix from $1,9502020-08-21 HIGH 7.2 CVE-2019-11853 Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4. Aleos 4.9.4 / 4.11.0+ Fix from $1,9502020-08-21 HIGH 7.2 CVE-2019-11858 Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Aleos after 4.12.0 Fix from $1,9502020-08-21 MEDIUM 6.7 CVE-2019-11849 A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code execution. Aleos 4.11.0+ Fix from $1,6002020-08-21 MEDIUM 6.7 CVE-2019-11850 A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution Aleos 4.11.0+ Fix from $1,6002020-08-21 HIGH 7.8 CVE-2020-8948 The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arb… Mobile Broadband Driver Package 5043+ Fix from $1,9502020-04-15 HIGH 7.1 CVE-2018-4064EPSS 14% An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. … Airlink Es450 Firmware No fix yet Fix from $1,9502019-10-31 HIGH 8.8 CVE-2018-4072EPSS 27% An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW… Airlink Es450 Firmware No fix yet Fix from $1,9502019-05-06 HIGH 8.8 CVE-2018-4073EPSS 26% An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW… Airlink Es450 Firmware No fix yet Fix from $1,9502019-05-06 HIGH 8.8 CVE-2018-4063 KEVEPSS 28% An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially craf… Aleos 4.4.9 / 4.9.4+ Fix from $1,9502019-05-06 HIGH 8.8 CVE-2018-4066 An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially… Airlink Es450 Firmware No fix yet Fix from $1,9502019-05-06 HIGH 8.8 CVE-2018-4070EPSS 18% An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F… Airlink Es450 Firmware No fix yet Fix from $1,9502019-05-06