First published: Fri Aug 21 2020(Updated: )
Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless ALEOS | <4.12.0 | |
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless AirLink MP70E | ||
Sierra Wireless AirLink RV50 | ||
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless ALEOS | <=4.9.4 | |
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX450 | ||
Sierra Wireless ALEOS | <=4.4.8 | |
Sierra Wireless AirLink ES440 | ||
Sierra Wireless AirLink GX400 | ||
Sierra Wireless GX440 | ||
Sierra Wireless AirLink LS300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11857 is a vulnerability in the AceManager of ALEOS before version 4.12.0, 4.9.5, and 4.4.9 that allows disclosure of sensitive system information.
CVE-2019-11857 has a severity rating of 4.9, which is classified as critical.
ACEOS versions before 4.12.0, 4.9.5, and 4.4.9 are affected by CVE-2019-11857.
To fix CVE-2019-11857, update your ACEOS software to version 4.12.0, 4.9.5, or 4.4.9.
You can find more information about CVE-2019-11857 in the Sierra Wireless Technical Bulletin - SWI-PSA-2020-004. (Link: https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2020-004/)