Sierrawireless
Sierrawireless Aleos Firmware: vulnerabilidades y CVE
Sierrawireless Aleos Firmware tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-5071 | Alta (8.8) | 1.7% | — | 10 abr 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root. |
| CVE-2016-5070 | Crítica (9.8) | 1.3% | — | 10 abr 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext. |
| CVE-2016-5069 | Crítica (9.8) | 1.4% | — | 10 abr 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL. |
| CVE-2016-5068 | Crítica (9.8) | 1.6% | — | 10 abr 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests. |
| CVE-2016-5067 | Alta (8.8) | 3.6% | — | 10 abr 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection. |
| CVE-2016-5066 | Crítica (9.8) | 1.8% | — | 10 abr 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user. |
| CVE-2016-5065 | Crítica (9.8) | 2.8% | — | 10 abr 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection. |