First published: Fri Aug 07 2020(Updated: )
The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless ALEOS | <4.4.9 | |
Sierra Wireless ALEOS | >=4.9.0<4.9.5 | |
Sierra Wireless AirLink ES440 | ||
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX400 | ||
Sierra Wireless GX440 | ||
Sierra Wireless AirLink GX450 | ||
Sierra Wireless AirLink LS300 | ||
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless AirLink MP70E | ||
Sierra Wireless AirLink RV50 | ||
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11862 is a vulnerability that allows traffic proxying on the SSH service on ALEOS versions before 4.12.0, 4.9.5, and 4.4.9.
CVE-2019-11862 has a severity value of 8.4, which is considered high.
ALEOS versions before 4.12.0, 4.9.5, and 4.4.9 are affected by CVE-2019-11862.
To fix CVE-2019-11862, upgrade to ALEOS version 4.12.0, 4.9.5, or 4.4.9 or higher.
More information about CVE-2019-11862 can be found at the following link: [Sierra Wireless Technical Bulletin - SWI-PSA-2019-004](https://source.sierrawireless.com/resources/airlink/software_reference_docs/technical-bulletin/sierra-wireless-technical-bulletin---swi-psa-2019-004/)