First published: Fri Aug 21 2020(Updated: )
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless ALEOS | <4.11.0 | |
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless AirLink MP70E | ||
Sierra Wireless AirLink RV50 | ||
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless ALEOS | <4.9.4 | |
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX450 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11853 is a vulnerability that allows for potential command injections in the AT command interface of ALEOS before version 4.11.0, and version 4.9.4.
Sierra Wireless Airlink Lx40 is not affected by CVE-2019-11853.
CVE-2019-11853 has a severity rating of 7.2, which is considered high.
To fix CVE-2019-11853, update ALEOS to version 4.11.0 or above.
You can find more information about CVE-2019-11853 in the Sierra Wireless Technical Bulletin - SWI-PSA-2020-004.