CVE-2018-4068: Infoleak
An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request can result in disclosure of the default configuration for the device. An attacker can send an unauthenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-4068?
CVE-2018-4068 is an exploitable information disclosure vulnerability in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3.
What is the severity of CVE-2018-4068?
CVE-2018-4068 has a severity rating of medium with a score of 5.3.
How does CVE-2018-4068 affect Sierra Wireless AirLink ES450 FW 4.9.3?
CVE-2018-4068 allows an attacker to disclose the default configuration of the device by sending an unauthenticated HTTP request.
Is Sierra Wireless AirLink ES450 FW 4.9.3 the only affected software?
Sierra Wireless AirLink ES450 FW 4.9.3 is the affected software for CVE-2018-4068.
How can I fix CVE-2018-4068?
To fix CVE-2018-4068, it is recommended to update Sierra Wireless AirLink ES450 FW to a version that is not affected.