First published: Fri Aug 21 2020(Updated: )
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless ALEOS | <4.11.0 | |
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless AirLink MP70E | ||
Sierra Wireless AirLink RV50 | ||
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless ALEOS | <4.9.4 | |
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX450 | ||
Sierra Wireless ALEOS | <4.4.9 | |
Sierra Wireless AirLink ES440 | ||
Sierra Wireless AirLink GX400 | ||
Sierra Wireless GX440 | ||
Sierra Wireless AirLink LS300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11847 is an improper privilege management vulnerability in ALEOS before version 4.11.0, 4.9.4, and 4.4.9.
The vulnerability allows an authenticated user to escalate their privileges to root via the command shell.
The severity of CVE-2019-11847 is high with a CVSS score of 7.8.
ALEOS versions before 4.11.0, 4.9.4, and 4.4.9 are affected by CVE-2019-11847.
To fix the vulnerability, you should update ALEOS to version 4.11.0, 4.9.4, or 4.4.9.