• News/
  • https://www.bleepingcomputer.com/news/security/sierra-21-vulnerabilities-impact-critical-infrastructure-routers/

"Sierra:21" vulnerabilities impact critical infrastructure routers

BleepingComputer
·
Bill Toulas
·
Published Dec 6, 2023
·
Updated

A set of 21 newly discovered vulnerabilities impact Sierra OT/IoT routers and threaten critical infrastructure with remote code execution, unauthorized access, cross-site scripting, authentication bypass, and denial of service attacks. The flaws discovered by Forescout Vedere Labs affect Sierra Wireless AirLink cellular routers and open-source components like TinyXML and OpenNDS (open Network Demarcation Service). AirLink routers are highly regarded in the field of industrial and mission-critical applications due to high-performance 3G/4G/5G and WiFi and multi-network connectivity. Various models are used in complex scenarios like passenger WiFi in transit systems, vehicle connectivity for emergency services, long-range gigabit connectivity to field operations, and various other performance-intensive tasks. Forescout says Sierra routers are found in government systems, emergency services, energy, transportation, water and wastewater facilities, manufacturing units, and healthcare organizations. Forescout’s researchers discovered 21 new vulnerabilities in Sierra AirLink cellular routers and the TinyXML and OpenNDS components, which are part of other products, too. Only one of the security issues has been rated critical, eight of them received a high severity score, and a dozen present a medium risk. The most noteworthy vulnerabilities are summarized below: For at least five of the above flaws, attackers do not require authentication to exploit them. For several others affecti...

Read full article

Affected Software

3 affected components
Sierra OT/IoT routers
Sierra Wireless AirLink cellular routers
OpenNDS open Network Demarcation Service
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of 21 vulnerabilities in Sierra OT/IoT routers that threaten critical infrastructure.

2

What security implications are discussed in the article?

The vulnerabilities pose risks such as remote code execution, unauthorized access, cross-site scripting, authentication bypass, and denial of service attacks.

3

What products or software are affected by these vulnerabilities?

The affected products include Sierra OT/IoT routers, Sierra Wireless AirLink cellular routers, and OpenNDS open Network Demarcation Service.

4

Who is the vendor of the affected routers mentioned in the article?

The vendor of the affected routers is Sierra.

5

What type of infrastructures are at risk due to these vulnerabilities?

Critical infrastructure is at risk due to these vulnerabilities in Sierra routers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203