← Back

Sierrawireless

sierrawireless

56 CVEs • 67 products

Products (67)

Click to collapse
Toggle
Aleos
aleos
Pinpoint X
pinpoint_x
Pinpoint Xt
pinpoint_xt
Raven X
raven_x
Raven X Ev Do
raven_x_ev-do
Raven Xe
raven_xe
Raven Xt
raven_xt
Gx440 Firmware
gx440_firmware
Es440 Firmware
es440_firmware
Ls300 Firmware
ls300_firmware
Gx400 Firmware
gx400_firmware
Es450 Firmware
es450_firmware
Rv50 Firmware
rv50_firmware
Rv50x Firmware
rv50x_firmware
Mp70 Firmware
mp70_firmware
Mp70e Firmware
mp70e_firmware
Gx450 Firmware
gx450_firmware
Mgos
mgos
Airlink Es440
airlink_es440
Airlink Es450
airlink_es450
Airlink Gx440
airlink_gx440
Airlink Gx450
airlink_gx450
Airlink Ls300
airlink_ls300
Es440
es440
Es450
es450
Gx400
gx400
Gx440
gx440
Gx450
gx450
Ls300
ls300
Gx 440
gx_440
Rv50
rv50
Rv50x
rv50x
Mp70
mp70
Mp70e
mp70e
Airlink Gx400
airlink_gx400
Airlink Lx40
airlink_lx40
Airlink Lx60
airlink_lx60
Airlink Mp70
airlink_mp70
Airlink Mp70e
airlink_mp70e
Airlink Rv50
airlink_rv50
Airlink Rv50x
airlink_rv50x
Airlink Rv55
airlink_rv55
Airlink Mg90
airlink_mg90
Lx40
lx40
Lx60
lx60
Rv55
rv55

CVEs (56)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sierrawireless
1Aleos
Nov 21, 2024
Aug 21, 2020
N/A· v4
3.8 LOW· v3
5.5 MEDIUM· v2
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same crede...Show more
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.Show less
1Sierrawireless
1Aleos
Nov 21, 2024
Aug 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.
1Sierrawireless
1Aleos
Nov 21, 2024
Aug 21, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
1Sierrawireless
1Aleos
Nov 21, 2024
Aug 21, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed via the ACEviewservice, accessible by default on the LAN.
1Sierrawireless
1Aleos
Nov 21, 2024
Aug 21, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution
1Sierrawireless
1Aleos
Nov 21, 2024
Aug 21, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code execution.
1Sierrawireless
1Aleos
Nov 21, 2024
Aug 21, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.
1Sierrawireless
1Aleos
Nov 21, 2024
Aug 21, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.
1Sierrawireless
1Mobile Broadband Driver Package
Nov 21, 2024
Apr 15, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage th...Show more
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage this vulnerability to execute arbitrary code with system privileges.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
Oct 31, 2019
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configur...Show more
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The the binary the endpoint /cgi-bin/Embeded_Ace_TLSet_Task.cgi...Show more
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The the binary the endpoint /cgi-bin/Embeded_Ace_TLSet_Task.cgi is a very similar endpoint that is designed for use with setting table values that can cause an arbitrary setting writes, resulting in the unverified changes to any system setting. An attacker can make an authenticated HTTP request, or run the binary as any user, to trigger this vulnerability.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task.cgi executable is used to change MSCII...Show more
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task.cgi executable is used to change MSCII configuration values within the configuration manager of the AirLink ES450. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using the /cgi-bin/Embedded_Ace_Set_Task.cgi endpoint.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceTLGet_Task.cgi executable is used to retrieve M...Show more
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceTLGet_Task.cgi executable is used to retrieve MSCII configuration values within the configuration manager of the AirLink ES450. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using the /cgi-bin/Embedded_Ace_TLGet_Task.cgi endpoint.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration setting...Show more
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using the /cgi-bin/Embedded_Ace_Get_Task.cgi endpoint.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a information leak, resul...Show more
An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a information leak, resulting in the disclosure of internal paths and files. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privil...Show more
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated requests being requested through an authenticated user. An attacker can get an authenticated user to request authenticated pages on the attacker's behalf to trigger this vulnerability.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript cod...Show more
An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript code execution, resulting in the execution of javascript code running on the victim's browser. An attacker can get a victim to click a link, or embedded URL, that redirects to the reflected cross-site scripting vulnerability to trigger this vulnerability.Show less
1Sierrawireless
1Aleos
Dec 15, 2025
May 6, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being...Show more
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting i...Show more
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user. An attacker can activate snmpd without any configuration changes to trigger this vulnerability.Show less
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web ser...Show more
An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web server. An attacker can listen to network traffic upstream from the device to capitalize on this vulnerability.Show less