First published: Mon Apr 10 2017(Updated: )
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos Firmware | =4.3.2 | |
Sierrawireless Gx 440 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5071 is considered a high severity vulnerability due to its potential for remote exploitation as it allows unauthorized access to the management web application.
To mitigate CVE-2016-5071, update the ALEOS firmware on Sierra Wireless GX 440 devices to a version that addresses the vulnerability.
CVE-2016-5071 affects Sierra Wireless GX 440 devices running ALEOS firmware version 4.3.2.
CVE-2016-5071 is a privilege escalation vulnerability that allows execution of the management web application with root privileges.
As a workaround for CVE-2016-5071, users can restrict access to the management web application through network segmentation or firewall rules until a firmware update can be applied.