First published: Fri Aug 07 2020(Updated: )
The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <4.4.9 | |
Sierrawireless Aleos | >=4.9.0<4.9.5 | |
Sierrawireless Airlink Es440 | ||
Sierrawireless Airlink Es450 | ||
Sierrawireless Airlink Gx400 | ||
Sierrawireless Airlink Gx440 | ||
Sierrawireless Airlink Gx450 | ||
Sierrawireless Airlink Ls300 | ||
Sierrawireless Airlink Lx40 | ||
Sierrawireless Airlink Lx60 | ||
Sierrawireless Airlink Mp70 | ||
Sierrawireless Airlink Mp70e | ||
Sierrawireless Airlink Rv50 | ||
Sierrawireless Airlink Rv50x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11862 is a vulnerability that allows traffic proxying on the SSH service on ALEOS versions before 4.12.0, 4.9.5, and 4.4.9.
CVE-2019-11862 has a severity value of 8.4, which is considered high.
ALEOS versions before 4.12.0, 4.9.5, and 4.4.9 are affected by CVE-2019-11862.
To fix CVE-2019-11862, upgrade to ALEOS version 4.12.0, 4.9.5, or 4.4.9 or higher.
More information about CVE-2019-11862 can be found at the following link: [Sierra Wireless Technical Bulletin - SWI-PSA-2019-004](https://source.sierrawireless.com/resources/airlink/software_reference_docs/technical-bulletin/sierra-wireless-technical-bulletin---swi-psa-2019-004/)