CVE-2019-11852
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed via the ACEviewservice, accessible by default on the LAN.
Affected (3)
Products: Sierrawireless: Aleos
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.13.0 |
| Running on/with | Platform Versions |
|---|---|
Sierrawireless Airlink Lx40 | All versions |
Sierrawireless Airlink Lx60 | All versions |
Sierrawireless Airlink Mp70 | All versions |
Sierrawireless Airlink Mp70e | All versions |
Sierrawireless Airlink Rv50 | All versions |
Sierrawireless Airlink Rv50x | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.9.5 |
| Running on/with | Platform Versions |
|---|---|
Sierrawireless Airlink Es450 | All versions |
Sierrawireless Airlink Gx450 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.9 |
| Running on/with | Platform Versions |
|---|---|
Sierrawireless Airlink Es440 | All versions |
Sierrawireless Airlink Gx400 | All versions |
Sierrawireless Airlink Gx440 | All versions |
Sierrawireless Airlink Ls300 | All versions |
References (2)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.