First published: Mon Dec 04 2023(Updated: )
The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.
Credit: security@sierrawireless.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Sierrawireless Aleos | <=4.16.0 | |
Any of | ||
Sierrawireless Es450 | ||
Sierrawireless Gx450 | ||
Sierrawireless Lx40 | ||
Sierrawireless Lx60 | ||
Sierrawireless Mp70 | ||
Sierrawireless Rv50x | ||
Sierrawireless Rv55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40460 is a vulnerability in the ACEManager component of ALEOS 4.16 and earlier that allows an authenticated user to perform client-side script execution within ACEManager, potentially altering the device functionality.
ALEOS versions up to and including 4.16.0 are affected by CVE-2023-40460.
CVE-2023-40460 has a severity rating of 7.1, which is considered high.
An authenticated user can exploit CVE-2023-40460 by uploading a file with a malicious name or type, which can result in client-side script execution within ACEManager.
Sierrawireless has released a security bulletin with details on mitigations for CVE-2023-40460. Please refer to the provided reference for more information.