First published: Fri Aug 21 2020(Updated: )
An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <4.12.0 | |
Sierrawireless Airlink Lx40 | ||
Sierrawireless Airlink Lx60 | ||
Sierrawireless Airlink Mp70 | ||
Sierrawireless Airlink Mp70e | ||
Sierrawireless Airlink Rv50 | ||
Sierrawireless Airlink Rv50x | ||
Sierrawireless Aleos | <4.9.5 | |
Sierrawireless Airlink Es450 | ||
Sierrawireless Airlink Gx450 | ||
Sierrawireless Aleos | <4.4.9 | |
Sierrawireless Airlink Es440 | ||
Sierrawireless Airlink Gx400 | ||
Sierrawireless Airlink Gx440 | ||
Sierrawireless Airlink Ls300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11855 is a vulnerability in the ALEOS gateway's LAN that allows remote code execution.
CVE-2019-11855 has a severity of 9.8, which is critical.
ALEOS versions before 4.12.0, 4.9.5, and 4.4.9 are affected by CVE-2019-11855.
To fix CVE-2019-11855, update to ALEOS version 4.12.0 or later.
You can find more information about CVE-2019-11855 in the Sierra Wireless technical bulletin: https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2020-004/