CVE-2022-46649
- EPSS 0.08%
- Published 10.02.2023 18:15:13
- Last modified 24.03.2025 16:15:16
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
CVE-2019-11851
- EPSS 0.03%
- Published 26.12.2022 22:15:10
- Last modified 16.04.2025 19:44:03
The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.
CVE-2020-8781
- EPSS 0%
- Published 06.10.2020 14:15:13
- Last modified 21.11.2024 05:39:25
Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.
CVE-2020-8782
- EPSS 8.43%
- Published 06.10.2020 14:15:13
- Last modified 21.11.2024 05:39:25
Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.
CVE-2019-11862
- EPSS 0.01%
- Published 21.08.2020 19:15:12
- Last modified 21.11.2024 04:21:55
The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.
- EPSS 0.02%
- Published 21.08.2020 19:15:11
- Last modified 21.11.2024 04:21:54
A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.
CVE-2019-11858
- EPSS 0.02%
- Published 21.08.2020 19:15:11
- Last modified 21.11.2024 04:21:54
Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.
CVE-2019-11857
- EPSS 0.02%
- Published 21.08.2020 19:15:11
- Last modified 21.11.2024 04:21:54
Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.
CVE-2019-11856
- EPSS 0.02%
- Published 21.08.2020 19:15:11
- Last modified 21.11.2024 04:21:54
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.
CVE-2019-11855
- EPSS 0.02%
- Published 21.08.2020 19:15:11
- Last modified 21.11.2024 04:21:54
An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.