CVE-2022-46649: OS Command Injection
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46649?
CVE-2022-46649 is a vulnerability in Acemanager in ALEOS before version 4.16 that allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
What software versions are affected by CVE-2022-46649?
CVE-2022-46649 affects Sierra Wireless Aleos versions up to and including 4.9.7 and 4.16.0.
How severe is CVE-2022-46649?
CVE-2022-46649 has a severity rating of 8.8 (high).
How can the vulnerability be exploited?
The vulnerability in Acemanager allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
How can I fix CVE-2022-46649?
To fix CVE-2022-46649, update your Acemanager software to version 4.16 or later.