5.5

CVE-2019-11856

A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SierrawirelessAleos Version <= 4.12.0
   SierrawirelessAirlink Lx40 Version-
   SierrawirelessAirlink Lx60 Version-
   SierrawirelessAirlink Mp70 Version-
   SierrawirelessAirlink Mp70e Version-
   SierrawirelessAirlink Rv50 Version-
   SierrawirelessAirlink Rv50x Version-
SierrawirelessAleos Version <= 4.9.4
   SierrawirelessAirlink Es450 Version-
   SierrawirelessAirlink Gx450 Version-
SierrawirelessAleos Version <= 4.4.8
   SierrawirelessAirlink Es440 Version-
   SierrawirelessAirlink Gx400 Version-
   SierrawirelessAirlink Gx440 Version-
   SierrawirelessAirlink Ls300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.039
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.8 1.2 2.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
nvd@nist.gov 5.5 8 4.9
AV:N/AC:L/Au:S/C:N/I:P/A:P
cve@mitre.org 3.3 0.7 2.5
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
CWE-294 Authentication Bypass by Capture-replay

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).