8.1

CVE-2023-40463

Use of Hard-Coded Credentials










When configured in
debugging mode by an authenticated user with



administrative
privileges, ALEOS 4.16 and earlier store the SHA512



hash of the common
root password for that version in a directory



accessible to a user
with root privileges or equivalent access.







Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SierrawirelessAleos Version <= 4.16.0
   SierrawirelessEs450 Version-
   SierrawirelessGx450 Version-
   SierrawirelessLx40 Version-
   SierrawirelessLx60 Version-
   SierrawirelessMp70 Version-
   SierrawirelessRv50x Version-
   SierrawirelessRv55 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.024
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
security@sierrawireless.com 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.