First published: Fri Aug 21 2020(Updated: )
Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <4.12.0 | |
Sierrawireless Airlink Lx40 | ||
Sierrawireless Airlink Lx60 | ||
Sierrawireless Airlink Mp70 | ||
Sierrawireless Airlink Mp70e | ||
Sierrawireless Airlink Rv50 | ||
Sierrawireless Airlink Rv50x | ||
Sierrawireless Aleos | <=4.9.4 | |
Sierrawireless Airlink Es450 | ||
Sierrawireless Airlink Gx450 | ||
Sierrawireless Aleos | <=4.4.8 | |
Sierrawireless Airlink Es440 | ||
Sierrawireless Airlink Gx400 | ||
Sierrawireless Airlink Gx440 | ||
Sierrawireless Airlink Ls300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11857 is a vulnerability in the AceManager of ALEOS before version 4.12.0, 4.9.5, and 4.4.9 that allows disclosure of sensitive system information.
CVE-2019-11857 has a severity rating of 4.9, which is classified as critical.
ACEOS versions before 4.12.0, 4.9.5, and 4.4.9 are affected by CVE-2019-11857.
To fix CVE-2019-11857, update your ACEOS software to version 4.12.0, 4.9.5, or 4.4.9.
You can find more information about CVE-2019-11857 in the Sierra Wireless Technical Bulletin - SWI-PSA-2020-004. (Link: https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2020-004/)