First published: Mon Apr 10 2017(Updated: )
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos Firmware | =4.3.2 | |
Sierrawireless Gx 440 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5065 is considered a critical vulnerability due to the potential for remote command injection.
To fix CVE-2016-5065, you should upgrade the ALEOS firmware on Sierra Wireless GX 440 devices to a version that is not vulnerable.
CVE-2016-5065 specifically affects Sierra Wireless GX 440 devices running ALEOS firmware version 4.3.2.
CVE-2016-5065 is a command injection vulnerability that allows attackers to execute arbitrary commands on the affected system.
If upgrading is not an option, implement strict network access controls and monitor for any suspicious activity to mitigate the risks associated with CVE-2016-5065.