A set of 21 newly discovered vulnerabilities impact Sierra OT/IoT routers and threaten critical infrastructure with remote code execution, unauthorized access, cross-site scripting, authentication bypass, and denial of service attacks. The flaws discovered by Forescout Vedere Labs affect Sierra Wireless AirLink cellular routers and open-source components like TinyXML and OpenNDS (open Network Demarcation Service). AirLink routers are highly regarded in the field of industrial and mission-critical applications due to high-performance 3G/4G/5G and WiFi and multi-network connectivity. Various models are used in complex scenarios like passenger WiFi in transit systems, vehicle connectivity for emergency services, long-range gigabit connectivity to field operations, and various other performance-intensive tasks. Forescout says Sierra routers are found in government systems, emergency services, energy, transportation, water and wastewater facilities, manufacturing units, and healthcare organizations. Forescout’s researchers discovered 21 new vulnerabilities in Sierra AirLink cellular routers and the TinyXML and OpenNDS components, which are part of other products, too. Only one of the security issues has been rated critical, eight of them received a high severity score, and a dozen present a medium risk. The most noteworthy vulnerabilities are summarized below: For at least five of the above flaws, attackers do not require authentication to exploit them. For several others affecti...
"Sierra:21" vulnerabilities impact critical infrastructure routers
BleepingComputer
·Bill Toulas
·Published Dec 6, 2023
·Updated
Affected Software
3 affected components
Sierra OT/IoT routers
Sierra Wireless AirLink cellular routers
OpenNDS open Network Demarcation Service
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of 21 vulnerabilities in Sierra OT/IoT routers that threaten critical infrastructure.
2
What security implications are discussed in the article?
The vulnerabilities pose risks such as remote code execution, unauthorized access, cross-site scripting, authentication bypass, and denial of service attacks.
3
What products or software are affected by these vulnerabilities?
The affected products include Sierra OT/IoT routers, Sierra Wireless AirLink cellular routers, and OpenNDS open Network Demarcation Service.
4
Who is the vendor of the affected routers mentioned in the article?
The vendor of the affected routers is Sierra.
5
What type of infrastructures are at risk due to these vulnerabilities?
Critical infrastructure is at risk due to these vulnerabilities in Sierra routers.