First published: Mon Apr 10 2017(Updated: )
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos Firmware | =4.3.2 | |
Sierrawireless Gx 440 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-5069 is classified as medium due to the potential for unauthorized access via guessable session tokens.
To fix CVE-2016-5069, update the Sierra Wireless GX 440 devices to a firmware version that does not utilize guessable session tokens.
CVE-2016-5069 affects Sierra Wireless GX 440 devices running ALEOS firmware version 4.3.2.
The implications of CVE-2016-5069 include the risk of session hijacking due to easily guessable session tokens in URLs.
Yes, ALEOS firmware version 4.3.2 is specifically identified as the vulnerable version associated with CVE-2016-5069.