First published: Fri Feb 10 2023(Updated: )
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
Credit: security@sierrawireless.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless ALEOS | <=4.9.7 | |
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX450 | ||
Sierra Wireless ALEOS | <=4.16.0 | |
Sierra Wireless AirLink LX40 | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless RV50 Firmware | ||
Sierra Wireless AirLink RV50X | ||
Sierra Wireless AirLink RV55 | ||
Sierra Wireless Airlink Router running ALEOS software | <=4.9.7 | |
Sierra Wireless Airlink Router running ALEOS software | <4.16.0 | 4.16.0 |
All of | ||
Sierra Wireless ALEOS | <=4.9.7 | |
Any of | ||
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX450 | ||
All of | ||
Sierra Wireless ALEOS | <=4.16.0 | |
Any of | ||
Sierra Wireless AirLink LX40 | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless RV50 Firmware | ||
Sierra Wireless AirLink RV50X | ||
Sierra Wireless AirLink RV55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46649 is a vulnerability in Acemanager in ALEOS before version 4.16 that allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
CVE-2022-46649 affects Sierra Wireless Aleos versions up to and including 4.9.7 and 4.16.0.
CVE-2022-46649 has a severity rating of 8.8 (high).
The vulnerability in Acemanager allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
To fix CVE-2022-46649, update your Acemanager software to version 4.16 or later.