First published: Mon Dec 26 2022(Updated: )
Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Mgos | <4.3 | |
Sierrawireless Airlink Mg90 | ||
Sierrawireless Mgos | <3.15.2 | |
Sierrawireless Airlink Omg2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13988 is a vulnerability in Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 that allows attackers to read log files via a Direct Request (aka Forced Browsing).
CVE-2019-13988 affects Sierra Wireless MGOS versions before 3.15.2 and 4.x before 4.3.
The severity of CVE-2019-13988 is medium, with a CVSS score of 6.5.
Attackers can exploit CVE-2019-13988 by performing a Direct Request (Forced Browsing) to read log files.
To fix CVE-2019-13988, it is recommended to update Sierra Wireless MGOS to version 3.15.2 or 4.3.