CVE-2019-11859: ALEOS SMS Handler Buffer Overflow
Published Aug 21, 2020
·Updated
A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.
Affected Software
15 affected components
Sierrawireless Aleos<=4.12.0
Sierrawireless Airlink Lx40
Sierrawireless Airlink Lx60
Sierrawireless Airlink Mp70
Sierrawireless Airlink Mp70e
Sierrawireless Airlink Rv50
Sierrawireless Airlink Rv50x
Sierrawireless Aleos<=4.9.4
Sierrawireless Airlink Es450
Sierrawireless Airlink Gx450
Sierrawireless Aleos<=4.4.8
Sierrawireless Airlink Es440
Sierrawireless Airlink Gx400
Sierrawireless Airlink Gx440
Sierrawireless Airlink Ls300
Event History
Aug 21, 2020
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2019-11859?
CVE-2019-11859 is a buffer overflow vulnerability in the SMS handler API of ALEOS before versions 4.13.0, 4.9.5, and 4.9.4, which may allow code execution as root.
2
What is the severity of CVE-2019-11859?
The severity of CVE-2019-11859 is critical with a CVSS score of 8.8.
3
Which software versions are affected by CVE-2019-11859?
The affected software versions are ALEOS before 4.13.0, 4.9.5, and 4.9.4.
4
How can CVE-2019-11859 be exploited?
CVE-2019-11859 can be exploited through the SMS handler API of ALEOS.
5
Is there a fix available for CVE-2019-11859?
To fix CVE-2019-11859, update ALEOS to a version equal to or later than 4.13.0, 4.9.5, or 4.9.4 as applicable.