First published: Fri Aug 21 2020(Updated: )
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <4.11.0 | |
Sierrawireless Airlink Lx40 | ||
Sierrawireless Airlink Lx60 | ||
Sierrawireless Airlink Mp70 | ||
Sierrawireless Airlink Mp70e | ||
Sierrawireless Airlink Rv50 | ||
Sierrawireless Airlink Rv50x | ||
Sierrawireless Aleos | <4.9.4 | |
Sierrawireless Airlink Es450 | ||
Sierrawireless Airlink Gx450 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11853 is a vulnerability that allows for potential command injections in the AT command interface of ALEOS before version 4.11.0, and version 4.9.4.
Sierra Wireless Airlink Lx40 is not affected by CVE-2019-11853.
CVE-2019-11853 has a severity rating of 7.2, which is considered high.
To fix CVE-2019-11853, update ALEOS to version 4.11.0 or above.
You can find more information about CVE-2019-11853 in the Sierra Wireless Technical Bulletin - SWI-PSA-2020-004.