CVE-2023-38321: Null Pointer Dereference
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /openndsauth/ that lacks a custom query string parameter and client-token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38321?
CVE-2023-38321 has a high severity as it allows remote attackers to crash the daemon and cause Captive Portal outages.
How do I fix CVE-2023-38321?
To fix CVE-2023-38321, upgrade your Sierra Wireless ALEOS to version 4.17.0.12 or later.
What types of attacks does CVE-2023-38321 allow?
CVE-2023-38321 enables denial of service attacks through a NULL pointer dereference caused by a specific GET request.
Which versions of ALEOS are affected by CVE-2023-38321?
CVE-2023-38321 affects all versions of Sierra Wireless ALEOS prior to 4.17.0.12.
What devices utilize OpenNDS and are affected by CVE-2023-38321?
Sierra Wireless devices utilizing OpenNDS such as ALEOS versions below 4.17.0.12 are affected by CVE-2023-38321.