CVE-2018-4064
- EPSS 0.04%
- Veröffentlicht 31.10.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:06:40
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an ...
CVE-2018-4072
- EPSS 41.98%
- Veröffentlicht 06.05.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:41
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task.cgi executable is used to change MSCII configuration values within th...
CVE-2018-4073
- EPSS 41.98%
- Veröffentlicht 06.05.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:42
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The the binary the endpoint /cgi-bin/Embeded_Ace_TLSet_Task.cgi is a very similar endpoint th...
CVE-2018-4062
- EPSS 0.31%
- Veröffentlicht 06.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:40
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged...
- EPSS 0.18%
- Veröffentlicht 06.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:40
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the...
CVE-2018-4065
- EPSS 0.05%
- Veröffentlicht 06.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:40
An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript code execution, resulting in the ...
CVE-2018-4066
- EPSS 71.85%
- Veröffentlicht 06.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:40
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, res...
CVE-2018-4067
- EPSS 0.45%
- Veröffentlicht 06.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:41
An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a information leak, resulting in the disclosure of inte...
CVE-2018-4070
- EPSS 38.87%
- Veröffentlicht 06.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:41
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration settings, so once the MSCIID is disco...
CVE-2018-4071
- EPSS 38.87%
- Veröffentlicht 06.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:41
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceTLGet_Task.cgi executable is used to retrieve MSCII configuration values with...