First published: Tue Oct 06 2020(Updated: )
Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <4.4.9 | |
Sierrawireless Aleos | >=4.5.0<4.9.5 | |
Sierrawireless Aleos | >=4.10.0<4.14.0 | |
Sierrawireless Airlink Es440 | ||
Sierrawireless Airlink Es450 | ||
Sierrawireless Airlink Gx400 | ||
Sierrawireless Airlink Gx440 | ||
Sierrawireless Airlink Gx450 | ||
Sierrawireless Airlink Ls300 | ||
Sierrawireless Airlink Lx40 | ||
Sierrawireless Airlink Lx60 | ||
Sierrawireless Airlink Mp70 | ||
Sierrawireless Airlink Mp70e | ||
Sierrawireless Airlink Rv50 | ||
Sierrawireless Airlink Rv50x | ||
Sierrawireless Airlink Rv55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8782 is a vulnerability that allows remote code execution on ALEOS versions before 4.4.9, 4.9.5, and 4.14.0.
CVE-2020-8782 has a severity rating of 9.8, which is classified as critical.
ALEOS versions before 4.4.9, 4.9.5, and 4.14.0 are affected by CVE-2020-8782.
To fix CVE-2020-8782, it is recommended to upgrade to ALEOS version 4.4.9 or later.
You can find more information about CVE-2020-8782 in the Sierra Wireless Technical Bulletin - SWI-PSA-2020-005.