First published: Fri Aug 21 2020(Updated: )
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless ALEOS | <=4.12.0 | |
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless AirLink MP70E | ||
Sierra Wireless AirLink RV50 | ||
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless ALEOS | <=4.9.4 | |
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX450 | ||
Sierra Wireless ALEOS | <=4.4.8 | |
Sierra Wireless AirLink ES440 | ||
Sierra Wireless AirLink GX400 | ||
Sierra Wireless GX440 | ||
Sierra Wireless AirLink LS300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.