Sierra Wireless RV55

CPE Details

Sierra Wireless RV55
-
2023-02-16
14h55 +00:00
2023-02-16
20h01 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:h:sierrawireless:rv55:-:*:*:*:*:*:*:*

Informations

Vendor

sierrawireless

Product

rv55

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-38321 2023-12-24 23h00 +00:00 OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.
7.5
High
CVE-2023-40465 2023-12-04 23h02 +00:00 Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.
8.3
High
CVE-2023-40464 2023-12-04 22h59 +00:00 Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.
8.1
High
CVE-2023-40463 2023-12-04 22h57 +00:00 When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.
8.1
High
CVE-2023-40462 2023-12-04 22h53 +00:00 The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
7.5
High
CVE-2023-40461 2023-12-04 22h52 +00:00 The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition.
8.1
High
CVE-2023-40460 2023-12-04 22h50 +00:00 The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.
7.1
High
CVE-2023-40459 2023-12-04 22h48 +00:00 The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
7.5
High
CVE-2022-46649 2023-02-10 00h00 +00:00 Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
8.8
High
CVE-2022-46650 2023-02-10 00h00 +00:00 Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
4.9
Medium