← Back

CVE-2019-11847

nvd nist
Published: Aug 21, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.

Affected (3)

Aleos
Configuration A
1 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Before 4.11.0
Running on/withPlatform Versions
Sierrawireless
Airlink Lx40
All versions
Sierrawireless
Airlink Lx60
All versions
Sierrawireless
Airlink Mp70
All versions
Sierrawireless
Airlink Mp70e
All versions
Sierrawireless
Airlink Rv50
All versions
Sierrawireless
Airlink Rv50x
All versions
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 4.9.4
Running on/withPlatform Versions
Sierrawireless
Airlink Es450
All versions
Sierrawireless
Airlink Gx450
All versions
Configuration C
1 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
Before 4.4.9
Running on/withPlatform Versions
Sierrawireless
Airlink Es440
All versions
Sierrawireless
Airlink Gx400
All versions
Sierrawireless
Airlink Gx440
All versions
Sierrawireless
Airlink Ls300
All versions

Timeline

No history available yet.