First published: Fri Feb 10 2023(Updated: )
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
Credit: security@sierrawireless.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <=4.9.7 | |
Sierrawireless Es450 | ||
Sierrawireless Gx450 | ||
Sierrawireless Aleos | <=4.16.0 | |
Sierrawireless Lx40 | ||
Sierrawireless Lx60 | ||
Sierrawireless Mp70 | ||
Sierrawireless Rv50 | ||
Sierrawireless Rv50x | ||
Sierrawireless Rv55 | ||
Sierra Wireless Airlink Router (ES450, GX450) running ALEOS software | <=4.9.7 | |
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | <4.16.0 | 4.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46649 is a vulnerability in Acemanager in ALEOS before version 4.16 that allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
CVE-2022-46649 affects Sierra Wireless Aleos versions up to and including 4.9.7 and 4.16.0.
CVE-2022-46649 has a severity rating of 8.8 (high).
The vulnerability in Acemanager allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
To fix CVE-2022-46649, update your Acemanager software to version 4.16 or later.