Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aleos HIGH 7.5
CVE-2023-38321

OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer der…

Fix: 4.17.0.12+
Fix from $1,950 2023-12-25
Aleos MEDIUM 6.8
CVE-2023-40464

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items coul…

Fix: after 4.16.0
Fix from $1,600 2023-12-04
Aleos MEDIUM 5.5
CVE-2023-40465

Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area netwo…

Fix: after 4.16.0
Fix from $1,600 2023-12-04
Aleos HIGH 7.2
CVE-2023-40463

When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the …

Fix: after 4.16.0
Fix from $1,950 2023-12-04
Aleos MEDIUM 5.4
CVE-2023-40460

The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authentica…

Fix: after 4.16.0
Fix from $1,600 2023-12-04
Aleos HIGH 7.5
CVE-2023-40459

The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially resu…

Fix: after 4.16.0
Fix from $1,950 2023-12-04
Aleos HIGH 7.5
CVE-2023-40458

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigg…

Fix: after 4.16.2
Fix from $1,950 2023-11-29
Aleos HIGH 8.8
CVE-2022-46649

Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell comman…

Fix: after 4.16.0
Fix from $1,950 2023-02-10
Aleos CRITICAL 9.8
CVE-2019-11851

The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote att…

Fix: 4.4.9 / 4.9.5+
Fix from $2,300 2022-12-26
Mgos MEDIUM 6.5
CVE-2019-13988

Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).

Fix: 3.15.2 / 4.3+
Fix from $1,600 2022-12-26
Airlink Mobility Manager CRITICAL 9.8
CVE-2020-11101

Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with a…

Fix: 2.17+
Fix from $2,300 2022-12-26
Aleos CRITICAL 9.8
CVE-2020-8782

Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.

Fix: 4.4.9 / 4.9.5+
Fix from $2,300 2020-10-06
Aleos HIGH 7.8
CVE-2020-8781

Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.

Fix: 4.14.0+
Fix from $1,950 2020-10-06
Aleos HIGH 8.4
CVE-2019-11862

The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.

Fix: 4.4.9 / 4.9.5+
Fix from $1,950 2020-08-21
Aleos CRITICAL 9.8
CVE-2019-11855

An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.

Fix: 4.4.9 / 4.9.5+
Fix from $2,300 2020-08-21
Aleos CRITICAL 9.1
CVE-2019-11852

An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed v…

Fix: 4.4.9 / 4.9.5+
Fix from $2,300 2020-08-21
Aleos HIGH 8.8
CVE-2019-11859

A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.

Fix: after 4.12.0
Fix from $1,950 2020-08-21
Aleos HIGH 7.8
CVE-2019-11847

An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the co…

Fix: 4.4.9 / 4.9.4+
Fix from $1,950 2020-08-21
Aleos HIGH 7.2
CVE-2019-11848

An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain use…

Fix: 4.4.9 / 4.9.5+
Fix from $1,950 2020-08-21
Aleos HIGH 7.2
CVE-2019-11853

Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.

Fix: 4.9.4 / 4.11.0+
Fix from $1,950 2020-08-21
Aleos HIGH 7.2
CVE-2019-11858

Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

Fix: after 4.12.0
Fix from $1,950 2020-08-21
Aleos MEDIUM 6.7
CVE-2019-11849

A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code execution.

Fix: 4.11.0+
Fix from $1,600 2020-08-21
Aleos MEDIUM 6.7
CVE-2019-11850

A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution

Fix: 4.11.0+
Fix from $1,600 2020-08-21
Mobile Broadband Driver Package HIGH 7.8
CVE-2020-8948

The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arb…

Fix: 5043+
Fix from $1,950 2020-04-15
Airlink Es450 Firmware HIGH 7.1
CVE-2018-4064EPSS 14%

An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. …

No fix yet
Fix from $1,950 2019-10-31
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4072EPSS 27%

An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…

No fix yet
Fix from $1,950 2019-05-06
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4073EPSS 26%

An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…

No fix yet
Fix from $1,950 2019-05-06
Aleos HIGH 8.8
CVE-2018-4063 KEVEPSS 28%

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially craf…

Fix: 4.4.9 / 4.9.4+
Fix from $1,950 2019-05-06
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4066

An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially…

No fix yet
Fix from $1,950 2019-05-06
Airlink Es450 Firmware HIGH 8.8
CVE-2018-4070EPSS 18%

An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…

No fix yet
Fix from $1,950 2019-05-06