First published: Mon Dec 04 2023(Updated: )
The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
Credit: security@sierrawireless.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sierra Wireless AirLink Cellular Routers | ||
Sierra Wireless AirLink Cellular Routers | ||
OpenNDS | ||
All of | ||
Sierra Wireless ALEOS | <=4.16.0 | |
Any of | ||
Sierra Wireless AirLink ES450 | ||
Sierra Wireless AirLink GX450 | ||
Sierra Wireless AirLink LX40 | ||
Sierra Wireless AirLink LX60 | ||
Sierra Wireless AirLink MP70 | ||
Sierra Wireless AirLink RV50X | ||
Sierra Wireless AirLink RV55 | ||
Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40462 is a vulnerability in the ACEManager component of ALEOS 4.16 and earlier, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions.
The severity of CVE-2023-40462 is high, with a severity value of 7.5.
The Sierra AirLink cellular routers with ALEOS 4.16 and earlier, TinyXML, and OpenNDS are affected by CVE-2023-40462.
CVE-2023-40462 can result in a Denial of Service (DoS) condition for ACEManager, while not impairing other router functions.
Sierra Wireless has released a technical bulletin with instructions on how to address CVE-2023-40462. Please refer to the provided reference link for more information.