First published: Fri Aug 21 2020(Updated: )
A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless ALEOS | <=4.12.0 | |
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless AirLink MP70E | ||
Sierra Wireless AirLink RV50 | ||
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless ALEOS | <=4.9.4 | |
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX450 | ||
Sierra Wireless ALEOS | <=4.4.8 | |
Sierra Wireless AirLink ES440 | ||
Sierra Wireless AirLink GX400 | ||
Sierra Wireless GX440 | ||
Sierra Wireless AirLink LS300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11859 is a buffer overflow vulnerability in the SMS handler API of ALEOS before versions 4.13.0, 4.9.5, and 4.9.4, which may allow code execution as root.
The severity of CVE-2019-11859 is critical with a CVSS score of 8.8.
The affected software versions are ALEOS before 4.13.0, 4.9.5, and 4.9.4.
CVE-2019-11859 can be exploited through the SMS handler API of ALEOS.
To fix CVE-2019-11859, update ALEOS to a version equal to or later than 4.13.0, 4.9.5, or 4.9.4 as applicable.