CVE-2023-40465: Improper input leads to DoS
Published Dec 4, 2023
·Updated
Several versions of ALEOS, including ALEOS 4.16.0, include an opensource
third-party component which can be exploited from the local
area network, resulting in a Denial of Service condition for the captive portal.
Affected Software
8 affected components
All of the following
Sierrawireless Aleos<=4.16.0
Any of the following
Sierrawireless Es450
Sierrawireless Gx450
Sierrawireless Lx40
Sierrawireless Lx60
Sierrawireless Mp70
Sierrawireless Rv50x
Sierrawireless Rv55
Event History
Dec 4, 2023
CVE Published
11:02 PM
Data Sourced
11:02 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-40465?
CVE-2023-40465 is a vulnerability in ALEOS that allows an attacker to cause a Denial of Service condition on the captive portal.
2
Which versions of ALEOS are affected by CVE-2023-40465?
Versions up to and including ALEOS 4.16.0 are affected by CVE-2023-40465.
3
What is the severity of CVE-2023-40465?
CVE-2023-40465 has a severity rating of 8.3 (High).
4
How can an attacker exploit CVE-2023-40465?
An attacker can exploit CVE-2023-40465 by leveraging a vulnerability in a third-party component over the local area network.
5
Is Sierrawireless Es450 vulnerable to CVE-2023-40465?
No, Sierrawireless Es450 is not vulnerable to CVE-2023-40465.