First published: Fri Aug 21 2020(Updated: )
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <=4.12.0 | |
Sierrawireless Airlink Lx40 | ||
Sierrawireless Airlink Lx60 | ||
Sierrawireless Airlink Mp70 | ||
Sierrawireless Airlink Mp70e | ||
Sierrawireless Airlink Rv50 | ||
Sierrawireless Airlink Rv50x | ||
Sierrawireless Aleos | <=4.9.4 | |
Sierrawireless Airlink Es450 | ||
Sierrawireless Airlink Gx450 | ||
Sierrawireless Aleos | <=4.4.8 | |
Sierrawireless Airlink Es440 | ||
Sierrawireless Airlink Gx400 | ||
Sierrawireless Airlink Gx440 | ||
Sierrawireless Airlink Ls300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.