CVE-2018-4069: Infoleak
An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web server. An attacker can listen to network traffic upstream from the device to capitalize on this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-4069?
CVE-2018-4069 is an information disclosure vulnerability that exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3.
What is the severity of CVE-2018-4069?
The severity of CVE-2018-4069 is high, with a severity value of 7.5.
How does CVE-2018-4069 impact Sierra Wireless AirLink ES450 FW 4.9.3?
CVE-2018-4069 allows an attacker to listen to plaintext XML authentication traffic, potentially exposing sensitive information.
How can I fix CVE-2018-4069 in Sierra Wireless AirLink ES450 FW 4.9.3?
To fix CVE-2018-4069, it is recommended to update Sierra Wireless AirLink ES450 to a version that includes a fix for the vulnerability.
Where can I find more information about CVE-2018-4069?
More information about CVE-2018-4069 can be found on the following references: [link1], [link2], [link3].