CVE-2019-11850: ALEOS AT Command Stack Overflow
Published Aug 21, 2020
·Updated
A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution
Affected Software
7 affected components
Sierrawireless Aleos<4.11.0
Sierrawireless Airlink Lx40
Sierrawireless Airlink Lx60
Sierrawireless Airlink Mp70
Sierrawireless Airlink Mp70e
Sierrawireless Airlink Rv50
Sierrawireless Airlink Rv50x
Event History
Aug 21, 2020
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2019-11850?
CVE-2019-11850 is a stack overflow vulnerability in the AT command interface of ALEOS before version 4.11.0.
2
What is the severity of CVE-2019-11850?
The severity of CVE-2019-11850 is medium with a CVSS score of 6.7.
3
How does CVE-2019-11850 affect Sierra Wireless Aleos before version 4.11.0?
Sierra Wireless Aleos before version 4.11.0 is affected by CVE-2019-11850 due to the stack overflow vulnerability in its AT command interface, which may allow code execution.
4
Is Sierra Wireless Airlink Lx40 affected by CVE-2019-11850?
Sierra Wireless Airlink Lx40 is not vulnerable to CVE-2019-11850.
5
How can I fix CVE-2019-11850?
To fix CVE-2019-11850, update ALEOS to version 4.11.0 or later.