8.8

CVE-2022-46649

Exploit
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sierrawireless ≫ Aleos Version <= 4.9.7
   Sierrawireless ≫ Es450 Version -
   Sierrawireless ≫ Gx450 Version -
Sierrawireless ≫ Aleos Version <= 4.16.0
   Sierrawireless ≫ Lx40 Version -
   Sierrawireless ≫ Lx60 Version -
   Sierrawireless ≫ Mp70 Version -
   Sierrawireless ≫ Rv50 Version -
   Sierrawireless ≫ Rv50x Version -
   Sierrawireless ≫ Rv55 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.3% 0.81
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-001/
Vendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-04
Third Party Advisory
US Government Resource
https://www.otorio.com/blog/airlink-acemanager-vulnerabilities/
Third Party Advisory
Exploit