First published: Fri Aug 21 2020(Updated: )
A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <=4.12.0 | |
Sierrawireless Airlink Lx40 | ||
Sierrawireless Airlink Lx60 | ||
Sierrawireless Airlink Mp70 | ||
Sierrawireless Airlink Mp70e | ||
Sierrawireless Airlink Rv50 | ||
Sierrawireless Airlink Rv50x | ||
Sierrawireless Aleos | <=4.9.4 | |
Sierrawireless Airlink Es450 | ||
Sierrawireless Airlink Gx450 | ||
Sierrawireless Aleos | <=4.4.8 | |
Sierrawireless Airlink Es440 | ||
Sierrawireless Airlink Gx400 | ||
Sierrawireless Airlink Gx440 | ||
Sierrawireless Airlink Ls300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11859 is a buffer overflow vulnerability in the SMS handler API of ALEOS before versions 4.13.0, 4.9.5, and 4.9.4, which may allow code execution as root.
The severity of CVE-2019-11859 is critical with a CVSS score of 8.8.
The affected software versions are ALEOS before 4.13.0, 4.9.5, and 4.9.4.
CVE-2019-11859 can be exploited through the SMS handler API of ALEOS.
To fix CVE-2019-11859, update ALEOS to a version equal to or later than 4.13.0, 4.9.5, or 4.9.4 as applicable.