CVE-2023-38321
- EPSS 0.04%
- Published 25.12.2023 09:15:07
- Last modified 21.11.2024 08:13:19
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a c...
CVE-2023-40465
- EPSS 0%
- Published 04.12.2023 23:15:26
- Last modified 21.11.2024 08:19:31
Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.
CVE-2023-40464
- EPSS 0.01%
- Published 04.12.2023 23:15:26
- Last modified 21.11.2024 08:19:31
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEMa...
CVE-2023-40463
- EPSS 0.02%
- Published 04.12.2023 23:15:25
- Last modified 21.11.2024 08:19:31
When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root priv...
CVE-2023-40462
- EPSS 0.01%
- Published 04.12.2023 23:15:25
- Last modified 13.02.2025 17:17:04
The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEM...
CVE-2023-40461
- EPSS 0.01%
- Published 04.12.2023 23:15:25
- Last modified 21.11.2024 08:19:31
The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting conditi...
CVE-2023-40460
- EPSS 0%
- Published 04.12.2023 23:15:25
- Last modified 21.11.2024 08:19:30
The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device ...
CVE-2023-40459
- EPSS 0.74%
- Published 04.12.2023 23:15:24
- Last modified 21.11.2024 08:19:30
The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router func...
CVE-2023-40458
- EPSS 0.03%
- Published 29.11.2023 23:15:20
- Last modified 21.11.2024 08:19:30
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. Thi...
CVE-2022-46650
- EPSS 0.19%
- Published 10.02.2023 18:15:13
- Last modified 24.03.2025 17:15:13
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.