CVE-2023-40462: Improper input leads to DoS
The ACEManager component of ALEOS 4.16 and earlier does not
perform input sanitization during authentication, which could
potentially result in a Denial of Service (DoS) condition for
ACEManager without impairing other router functions. ACEManager
recovers from the DoS condition by restarting within ten seconds of
becoming unavailable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40462?
CVE-2023-40462 is a vulnerability in the ACEManager component of ALEOS 4.16 and earlier, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions.
What is the severity of CVE-2023-40462?
The severity of CVE-2023-40462 is high, with a severity value of 7.5.
What software is affected by CVE-2023-40462?
The Sierra AirLink cellular routers with ALEOS 4.16 and earlier, TinyXML, and OpenNDS are affected by CVE-2023-40462.
How does CVE-2023-40462 impact ACEManager?
CVE-2023-40462 can result in a Denial of Service (DoS) condition for ACEManager, while not impairing other router functions.
Is there a fix for CVE-2023-40462?
Sierra Wireless has released a technical bulletin with instructions on how to address CVE-2023-40462. Please refer to the provided reference link for more information.