First published: Fri Feb 10 2023(Updated: )
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
Credit: security@sierrawireless.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <=4.9.7 | |
Sierrawireless Es450 | ||
Sierrawireless Gx450 | ||
Sierrawireless Aleos | <=4.16.0 | |
Sierrawireless Lx40 | ||
Sierrawireless Lx60 | ||
Sierrawireless Mp70 | ||
Sierrawireless Rv50 | ||
Sierrawireless Rv50x | ||
Sierrawireless Rv55 | ||
Sierra Wireless Airlink Router (ES450, GX450) running ALEOS software | <=4.9.7 | |
Sierra Wireless Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software | <4.16.0 | 4.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46650 is a vulnerability in Acemanager in ALEOS before version 4.16 that allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
CVE-2022-46650 affects ALEOS versions up to and including 4.9.7 and ALEOS version 4.16.0.
The severity of CVE-2022-46650 is medium with a CVSS score of 4.9.
To fix CVE-2022-46650, upgrade to version 4.16.0 or higher of ALEOS.
You can find more information about CVE-2022-46650 in the Sierra Wireless technical bulletin and the CISA advisory.