First published: Mon Dec 04 2023(Updated: )
Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.
Credit: security@sierrawireless.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Sierrawireless Aleos | <=4.16.0 | |
Any of | ||
Sierrawireless Es450 | ||
Sierrawireless Gx450 | ||
Sierrawireless Lx40 | ||
Sierrawireless Lx60 | ||
Sierrawireless Mp70 | ||
Sierrawireless Rv50x | ||
Sierrawireless Rv55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40465 is a vulnerability in ALEOS that allows an attacker to cause a Denial of Service condition on the captive portal.
Versions up to and including ALEOS 4.16.0 are affected by CVE-2023-40465.
CVE-2023-40465 has a severity rating of 8.3 (High).
An attacker can exploit CVE-2023-40465 by leveraging a vulnerability in a third-party component over the local area network.
No, Sierrawireless Es450 is not vulnerable to CVE-2023-40465.