First published: Mon Dec 04 2023(Updated: )
The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
Credit: security@sierrawireless.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Sierrawireless Aleos | <=4.16.0 | |
Any of | ||
Sierrawireless Es450 | ||
Sierrawireless Gx450 | ||
Sierrawireless Lx40 | ||
Sierrawireless Lx60 | ||
Sierrawireless Mp70 | ||
Sierrawireless Rv50x | ||
Sierrawireless Rv55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40459 is a vulnerability in the ACEManager component of ALEOS 4.16 and earlier that allows for improper input leading to a Denial of Service (DoS) condition.
Sierrawireless Aleos versions up to 4.16.0 are affected by CVE-2023-40459.
CVE-2023-40459 is considered to have a severity level of 7.5 (high).
To exploit CVE-2023-40459, an attacker can send specially crafted input during the authentication process in ACEManager, which can cause a DoS condition.
Sierrawireless has released a fix for CVE-2023-40459. It is recommended to update to a version of ALEOS that is later than 4.16.0.