7.5

CVE-2023-40459









The
ACEManager component of ALEOS 4.16 and earlier does not adequately perform
input sanitization during authentication, which could potentially result in a
Denial of Service (DoS) condition for ACEManager without impairing other router
functions. ACEManager recovers from the DoS condition by restarting within ten
seconds of becoming unavailable.






Data is provided by the National Vulnerability Database (NVD)
SierrawirelessAleos Version <= 4.16.0
   SierrawirelessEs450 Version-
   SierrawirelessGx450 Version-
   SierrawirelessLx40 Version-
   SierrawirelessLx60 Version-
   SierrawirelessMp70 Version-
   SierrawirelessRv50x Version-
   SierrawirelessRv55 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.74% 0.716
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security@sierrawireless.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.