CVE-2019-11849: ALEOS AT API Stack Overflow
Published Aug 21, 2020
·Updated
A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code execution.
Affected Software
7 affected components
Sierrawireless Aleos<4.11.0
Sierrawireless Airlink Lx40
Sierrawireless Airlink Lx60
Sierrawireless Airlink Mp70
Sierrawireless Airlink Mp70e
Sierrawireless Airlink Rv50
Sierrawireless Airlink Rv50x
Event History
Aug 21, 2020
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2019-11849?
CVE-2019-11849 is a stack overflow vulnerability in the AT command APIs of ALEOS before 4.11.0.
2
What software versions are affected by CVE-2019-11849?
ALEOS versions before 4.11.0 are affected by CVE-2019-11849.
3
What is the severity of CVE-2019-11849?
CVE-2019-11849 has a severity level of medium with a CVSS score of 6.7.
4
How can I fix the CVE-2019-11849 vulnerability?
To fix the CVE-2019-11849 vulnerability, upgrade ALEOS to version 4.11.0 or later.
5
Where can I find more information about CVE-2019-11849?
You can find more information about CVE-2019-11849 at the following link: [Sierra Wireless Technical Bulletin - SWI-PSA-2020-004](https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2020-004/)