First published: Fri Jun 30 2017(Updated: )
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless Airlink Raven Xe Firmware | <=- | |
Sierra Wireless AirLink Raven XE | ||
Sierra Wireless Airlink Raven Xt Firmware | ||
Sierra Wireless Airlink Raven Xt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6044 has been classified as a high severity vulnerability due to improper authorization that allows unauthorized access.
To fix CVE-2017-6044, update the Sierra Wireless AirLink Raven XE to firmware version 4.0.14 or higher and the AirLink Raven XT to version 4.0.11 or higher.
The risks of CVE-2017-6044 include unauthorized access to sensitive files and directories, allowing attackers to perform privileged actions.
CVE-2017-6044 affects all versions of Sierra Wireless AirLink Raven XE prior to 4.0.14 and AirLink Raven XT prior to 4.0.11.
While specific exploitation details are not publicly disclosed, the vulnerability's nature indicates that it could be leveraged by remote attackers to exploit the affected devices.