First published: Thu Apr 21 2016(Updated: )
ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <=4.4.2 | |
Sierrawireless Es440 | ||
Sierrawireless Es450 | ||
Sierrawireless Gx400 | ||
Sierrawireless Gx440 | ||
Sierrawireless Gx450 | ||
Sierrawireless Ls300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6479 is categorized as having a medium severity level due to potential exposure of sensitive boot-sequence information.
CVE-2015-6479 allows remote attackers to read the filteredlogs.txt file on affected Sierra Wireless devices, potentially revealing sensitive information.
CVE-2015-6479 affects ALEOS versions up to and including 4.4.2 on specified Sierra Wireless devices.
To mitigate CVE-2015-6479, it is recommended to upgrade to a version of ALEOS later than 4.4.2 that addresses this vulnerability.
CVE-2015-6479 impacts the Sierra Wireless ES440, ES450, GX400, GX440, GX450, and LS300 devices with ALEOS version 4.4.2 or earlier.