« Volver al listado

CVE-2023-40460

Estado: ModificadaMedia (5.4)—

The ACEManager component of ALEOS 4.16 and earlier does not

validate uploaded file names and types, which could potentially allow

an authenticated user to perform client-side script execution within

ACEManager, altering the device functionality until the device is

restarted.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-40460",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-40460",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2023-12-23T05:01:09.507493Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@sierrawireless.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security@sierrawireless.com",
      "affectedData": [
        {
          "vendor": "SierraWireless",
          "product": "ALEOS",
          "versions": [
            {
              "status": "affected",
              "version": "4.10",
              "versionType": "Custom",
              "lessThanOrEqual": "4.16"
            },
            {
              "status": "affected",
              "version": "0",
              "versionType": "Custom",
              "lessThanOrEqual": "4.9.8"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-04T23:15:25.180",
  "references": [
    {
      "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006/#sthash.5ZcnyPM1.dpbs",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@sierrawireless.com"
    },
    {
      "url": "https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006/#sthash.5ZcnyPM1.dpbs",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@sierrawireless.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        },
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\n\n\n\n\n\n\n\n\n\nThe ACEManager\ncomponent of ALEOS 4.16 and earlier does not\n\n\n\nvalidate uploaded\nfile names and types, which could potentially allow\n\n\n\nan authenticated\nuser to perform client-side script execution within\n\n\n\nACEManager, altering\nthe device functionality until the device is\n\n\n\nrestarted.\n\n\n\n\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "El componente ACEManager de ALEOS 4.16 y versiones anteriores no valida los nombres y tipos de archivos cargados, lo que podría permitir a un usuario autenticado realizar la ejecución de scripts del lado del cliente dentro de ACEManager, alterando la funcionalidad del dispositivo hasta que se reinicie."
    }
  ],
  "lastModified": "2026-06-17T06:17:57.597",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45265DDA-E10F-49D0-B2C6-FC123C42E5AE",
              "versionEndIncluding": "4.16.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sierrawireless:es450:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "524DF1AE-21F2-4AA6-99E7-6F98304FF845"
            },
            {
              "criteria": "cpe:2.3:h:sierrawireless:gx450:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2C12CF71-FE0E-44EA-9F2E-7CFB42E7C216"
            },
            {
              "criteria": "cpe:2.3:h:sierrawireless:lx40:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "069DD303-C100-4FAF-BD6B-4EE61CBDE9F7"
            },
            {
              "criteria": "cpe:2.3:h:sierrawireless:lx60:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2A3B7B3D-1594-434B-8E22-01C67DF54F16"
            },
            {
              "criteria": "cpe:2.3:h:sierrawireless:mp70:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "007D4629-4BE2-4C7A-AC8B-E87739E22D12"
            },
            {
              "criteria": "cpe:2.3:h:sierrawireless:rv50x:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "61D3EF27-E823-4E49-BD58-D050EB02D294"
            },
            {
              "criteria": "cpe:2.3:h:sierrawireless:rv55:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "215BD4AB-8EFD-4F82-ABE4-E7F81AD528C2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@sierrawireless.com"
}