CVE-2018-4064: High severity sierra wireless airlink es450 firmware vulnerability
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-4064?
CVE-2018-4064 is an exploitable unverified password change vulnerability in the ACEManager upload.cgi function of Sierra Wireless AirLink ES450 FW 4.9.3.
How severe is CVE-2018-4064?
CVE-2018-4064 has a severity rating of 7.1 (high).
What software versions are affected by CVE-2018-4064?
Sierra Wireless AirLink ES450 FW 4.9.3 is affected by CVE-2018-4064.
How can CVE-2018-4064 be exploited?
CVE-2018-4064 can be exploited by sending a specially crafted HTTP request to the ACEManager upload.cgi function.
Is there a fix for CVE-2018-4064?
A fix or security patch for CVE-2018-4064 is not mentioned in the provided information. It is recommended to check with the vendor for updates or mitigation measures.