First published: Fri Feb 10 2023(Updated: )
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
Credit: security@sierrawireless.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless ALEOS | <=4.9.7 | |
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX450 | ||
Sierra Wireless ALEOS | <=4.16.0 | |
Sierra Wireless AirLink LX40 | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless RV50 Firmware | ||
Sierra Wireless AirLink RV50X | ||
Sierra Wireless AirLink RV55 | ||
Sierra Wireless Airlink Router running ALEOS software | <=4.9.7 | |
Sierra Wireless Airlink Router running ALEOS software | <4.16.0 | 4.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46650 is a vulnerability in Acemanager in ALEOS before version 4.16 that allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
CVE-2022-46650 affects ALEOS versions up to and including 4.9.7 and ALEOS version 4.16.0.
The severity of CVE-2022-46650 is medium with a CVSS score of 4.9.
To fix CVE-2022-46650, upgrade to version 4.16.0 or higher of ALEOS.
You can find more information about CVE-2022-46650 in the Sierra Wireless technical bulletin and the CISA advisory.