First published: Fri Jun 30 2017(Updated: )
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently protected during transmission and vulnerable to sniffing, which could lead to information disclosure.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless Airlink Raven Xe Firmware | <=- | |
Sierra Wireless AirLink Raven XE | ||
Sierra Wireless Airlink Raven Xt Firmware | ||
Sierra Wireless Airlink Raven Xt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6046 has been classified with a moderate severity level due to the risk of sensitive information exposure during transmission.
To fix CVE-2017-6046, update the Sierra Wireless AirLink Raven XE firmware to version 4.0.14 or later, and the Raven XT firmware to version 4.0.11 or later.
CVE-2017-6046 affects the Sierra Wireless AirLink Raven XE and Raven XT devices running firmware versions prior to 4.0.14 and 4.0.11, respectively.
The consequences of CVE-2017-6046 include the potential exposure of sensitive information due to insufficient protection during data transmission.
CVE-2017-6046 is more related to local network vulnerabilities, as attackers would need access to sniff the unprotected transmissions.