CVE-2016-5070: Critical severity sierra wireless aleos firmware vulnerability
Published Apr 10, 2017
·Updated
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext.
Affected Software
2 affected components
Sierrawireless Aleos Firmware=4.3.2
Sierrawireless Gx 440
Event History
Apr 10, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-5070?
CVE-2016-5070 has a medium severity rating due to the potential for unauthorized access since passwords are stored in cleartext.
2
How do I fix CVE-2016-5070?
To fix CVE-2016-5070, update the ALEOS firmware to a version that does not store passwords in cleartext.
3
Which devices are affected by CVE-2016-5070?
CVE-2016-5070 affects Sierra Wireless GX 440 devices running ALEOS firmware version 4.3.2.
4
What is the impact of CVE-2016-5070 on security?
The impact of CVE-2016-5070 is significant as it allows attackers to retrieve stored passwords, compromising device security.
5
Is there a known exploit for CVE-2016-5070?
As of now, there are no public exploits specifically targeting CVE-2016-5070, but the vulnerability itself poses a risk.