First published: Mon May 06 2019(Updated: )
An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web server. An attacker can listen to network traffic upstream from the device to capitalize on this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Airlink Es450 Firmware | =4.9.3 | |
Sierrawireless Airlink Es450 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4069 is an information disclosure vulnerability that exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3.
The severity of CVE-2018-4069 is high, with a severity value of 7.5.
CVE-2018-4069 allows an attacker to listen to plaintext XML authentication traffic, potentially exposing sensitive information.
To fix CVE-2018-4069, it is recommended to update Sierra Wireless AirLink ES450 to a version that includes a fix for the vulnerability.
More information about CVE-2018-4069 can be found on the following references: [link1], [link2], [link3].