First published: Fri Aug 21 2020(Updated: )
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <4.11.0 | |
Sierrawireless Airlink Lx40 | ||
Sierrawireless Airlink Lx60 | ||
Sierrawireless Airlink Mp70 | ||
Sierrawireless Airlink Mp70e | ||
Sierrawireless Airlink Rv50 | ||
Sierrawireless Airlink Rv50x | ||
Sierrawireless Aleos | <4.9.4 | |
Sierrawireless Airlink Es450 | ||
Sierrawireless Airlink Gx450 | ||
Sierrawireless Aleos | <4.4.9 | |
Sierrawireless Airlink Es440 | ||
Sierrawireless Airlink Gx400 | ||
Sierrawireless Airlink Gx440 | ||
Sierrawireless Airlink Ls300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11847 is an improper privilege management vulnerability in ALEOS before version 4.11.0, 4.9.4, and 4.4.9.
The vulnerability allows an authenticated user to escalate their privileges to root via the command shell.
The severity of CVE-2019-11847 is high with a CVSS score of 7.8.
ALEOS versions before 4.11.0, 4.9.4, and 4.4.9 are affected by CVE-2019-11847.
To fix the vulnerability, you should update ALEOS to version 4.11.0, 4.9.4, or 4.4.9.