First published: Mon Dec 25 2023(Updated: )
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Sierrawireless Aleos | <4.17.0.12 | |
Any of | ||
Sierrawireless Lx40 | ||
Sierrawireless Lx60 | ||
Sierrawireless Mp70 | ||
Sierrawireless Rv50x | ||
Sierrawireless Rv55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.