Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-38321
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer der…
Aleos
4.17.0.12+
MEDIUM 6.8
CVE-2023-40464
Several versions of
ALEOS, including ALEOS 4.16.0, use a hardcoded
SSL certificate and
private key. An attacker with access to these items
coul…
Aleos
after 4.16.0
MEDIUM 5.5
CVE-2023-40465
Several versions of
ALEOS, including ALEOS 4.16.0, include an opensource
third-party
component which can be exploited from the local
area netwo…
Aleos
after 4.16.0
HIGH 7.2
CVE-2023-40463
When configured in
debugging mode by an authenticated user with
administrative
privileges, ALEOS 4.16 and earlier store the SHA512
hash of the …
Aleos
after 4.16.0
MEDIUM 5.4
CVE-2023-40460
The ACEManager
component of ALEOS 4.16 and earlier does not
validate uploaded
file names and types, which could potentially allow
an authentica…
Aleos
after 4.16.0
HIGH 7.5
CVE-2023-40459
The
ACEManager component of ALEOS 4.16 and earlier does not adequately perform
input sanitization during authentication, which could potentially resu…
Aleos
after 4.16.0
HIGH 7.5
CVE-2023-40458
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigg…
Aleos
after 4.16.2
HIGH 8.8
CVE-2022-46649
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell comman…
Aleos
after 4.16.0
CRITICAL 9.8
CVE-2019-11851
The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote att…
Aleos
4.4.9 / 4.9.5+
MEDIUM 6.5
CVE-2019-13988
Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).
Mgos
3.15.2 / 4.3+
CRITICAL 9.8
CVE-2020-11101
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with a…
Airlink Mobility Manager
2.17+
CRITICAL 9.8
CVE-2020-8782
Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.
Aleos
4.4.9 / 4.9.5+
HIGH 7.8
CVE-2020-8781
Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.
Aleos
4.14.0+
HIGH 8.4
CVE-2019-11862
The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.
Aleos
4.4.9 / 4.9.5+
CRITICAL 9.8
CVE-2019-11855
An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.
Aleos
4.4.9 / 4.9.5+
CRITICAL 9.1
CVE-2019-11852
An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed v…
Aleos
4.4.9 / 4.9.5+
HIGH 8.8
CVE-2019-11859
A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.
Aleos
after 4.12.0
HIGH 7.8
CVE-2019-11847
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the co…
Aleos
4.4.9 / 4.9.4+
HIGH 7.2
CVE-2019-11848
An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain use…
Aleos
4.4.9 / 4.9.5+
HIGH 7.2
CVE-2019-11853
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
Aleos
4.9.4 / 4.11.0+
HIGH 7.2
CVE-2019-11858
Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.
Aleos
after 4.12.0
MEDIUM 6.7
CVE-2019-11849
A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code execution.
Aleos
4.11.0+
MEDIUM 6.7
CVE-2019-11850
A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution
Aleos
4.11.0+
HIGH 7.8
CVE-2020-8948
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arb…
Mobile Broadband Driver Package
5043+
HIGH 7.1
CVE-2018-4064EPSS 14%
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. …
Airlink Es450 Firmware
No fix yet
HIGH 8.8
CVE-2018-4072EPSS 27%
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…
Airlink Es450 Firmware
No fix yet
HIGH 8.8
CVE-2018-4073EPSS 26%
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…
Airlink Es450 Firmware
No fix yet
HIGH 8.8
CVE-2018-4063 KEVEPSS 28%
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially craf…
Aleos
4.4.9 / 4.9.4+
HIGH 8.8
CVE-2018-4066
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially…
Airlink Es450 Firmware
No fix yet
HIGH 8.8
CVE-2018-4070EPSS 18%
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…
Airlink Es450 Firmware
No fix yet