7.5
CVE-2023-40459
- EPSS 0.74%
- Published 04.12.2023 23:15:24
- Last modified 21.11.2024 08:19:30
- Source security@sierrawireless.com
- Teams watchlist Login
- Open Login
The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
Data is provided by the National Vulnerability Database (NVD)
Sierrawireless ≫ Aleos Version <= 4.16.0
Sierrawireless ≫ Es450 Version-
Sierrawireless ≫ Gx450 Version-
Sierrawireless ≫ Lx40 Version-
Sierrawireless ≫ Lx60 Version-
Sierrawireless ≫ Mp70 Version-
Sierrawireless ≫ Rv50x Version-
Sierrawireless ≫ Rv55 Version-
Sierrawireless ≫ Gx450 Version-
Sierrawireless ≫ Lx40 Version-
Sierrawireless ≫ Lx60 Version-
Sierrawireless ≫ Mp70 Version-
Sierrawireless ≫ Rv50x Version-
Sierrawireless ≫ Rv55 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.74% | 0.716 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
security@sierrawireless.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.