CVE-2019-11856
3.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Exploitability: 1.2 / Impact: 2.5
Source: NVD
Description
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.
Affected (3)
Products: Sierrawireless: Aleos
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.12.0 |
| Running on/with | Platform Versions |
|---|---|
Sierrawireless Airlink Lx40 | All versions |
Sierrawireless Airlink Lx60 | All versions |
Sierrawireless Airlink Mp70 | All versions |
Sierrawireless Airlink Mp70e | All versions |
Sierrawireless Airlink Rv50 | All versions |
Sierrawireless Airlink Rv50x | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.9.4 |
| Running on/with | Platform Versions |
|---|---|
Sierrawireless Airlink Es450 | All versions |
Sierrawireless Airlink Gx450 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.4.8 |
| Running on/with | Platform Versions |
|---|---|
Sierrawireless Airlink Es440 | All versions |
Sierrawireless Airlink Gx400 | All versions |
Sierrawireless Airlink Gx440 | All versions |
Sierrawireless Airlink Ls300 | All versions |
References (2)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.