CVE-2018-4063: Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Other sources
Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.4.9 - Upgrade
Upgrade
Sierra Wireless AirLink ALEOSto a version that resolves this vulnerability.Fixed in 4.4.9 - Compensating control
Discontinue use of the product if mitigations are unavailable (Users should discontinue product utilization of Sierra Wireless AirLink ALEOS / AirLink ES450).
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is CVE-2018-4063?
CVE-2018-4063 is an exploitable remote code execution vulnerability in the upload.cgi functionality of Sierra Wireless AirLink ES450 Firmware 4.9.3.
What is the severity of CVE-2018-4063?
The severity of CVE-2018-4063 is critical with a CVSS score of 8.8.
What is the affected software for CVE-2018-4063?
The affected software for CVE-2018-4063 is Sierra Wireless AirLink ES450 Firmware 4.9.3.
How does CVE-2018-4063 work?
CVE-2018-4063 can be exploited by using a specially crafted HTTP request to upload a file, resulting in executable code being uploaded to the webserver.
Are there any references for CVE-2018-4063?
Yes, here are some references for CVE-2018-4063: [1](http://packetstormsecurity.com/files/152648/Sierra-Wireless-AirLink-ES450-ACEManager-upload.cgi-Remote-Code-Execution.html), [2](http://www.securityfocus.com/bid/108147), [3](https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03).