Sierrawireless
Sierrawireless Airlink Es450 Firmware: vulnerabilidades y CVE
Sierrawireless Airlink Es450 Firmware tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-4064 | Alta (7.1) | 14% | — | 31 oct 2019 | An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device… |
| CVE-2018-4073 | Alta (8.8) | 26% | — | 6 may 2019 | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The the binary the endpoint… |
| CVE-2018-4072 | Alta (8.8) | 26% | — | 6 may 2019 | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task.cgi executable is used to change MSCII… |
| CVE-2018-4071 | Alta (8.8) | 18% | — | 6 may 2019 | An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceTLGet_Task.cgi executable is used to retrieve… |
| CVE-2018-4070 | Alta (8.8) | 18% | — | 6 may 2019 | An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration… |
| CVE-2018-4067 | Media (6.5) | 4.1% | — | 6 may 2019 | An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a information leak,… |
| CVE-2018-4066 | Alta (8.8) | 1.9% | — | 6 may 2019 | An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform… |
| CVE-2018-4065 | Media (6.1) | 4.9% | — | 6 may 2019 | An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript… |
| CVE-2018-4062 | Alta (8.1) | 5.3% | — | 6 may 2019 | A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting… |
| CVE-2018-4069 | Alta (7.5) | 4.1% | — | 6 may 2019 | An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web… |
| CVE-2018-4068 | Media (5.3) | 11% | — | 6 may 2019 | An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request can result in disclosure of the default configuration for the device.… |
| CVE-2018-4061 | Alta (8.8) | 19% | — | 6 may 2019 | An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in… |