First published: Mon Apr 10 2017(Updated: )
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless Aleos Firmware | =4.3.2 | |
Sierra Wireless Gx 440 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5068 is a vulnerability in Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 that allows unauthorized access to Embedded_Ace_Get_Task.cgi requests without authentication.
CVE-2016-5068 affects users of Sierra Wireless GX 440 devices running ALEOS firmware version 4.3.2.
The impact of CVE-2016-5068 includes the potential for attackers to gain access to sensitive device configurations and data without proper authentication.
To resolve CVE-2016-5068, users should upgrade their ALEOS firmware to a version that addresses this vulnerability.
There are no documented workarounds for CVE-2016-5068, so upgrading the firmware is recommended.