CVE-2019-11856
Summary
| CVE | CVE-2019-11856 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-21 19:15:00 UTC |
| Updated | 2022-02-09 19:28:00 UTC |
| Description | A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials. |
Risk And Classification
Problem Types: CWE-294
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sierawireless | Airlink Es440 | - | All | All | All |
| Hardware | Sierawireless | Airlink Es440 | - | All | All | All |
| Hardware | Sierawireless | Airlink Es450 | - | All | All | All |
| Hardware | Sierawireless | Airlink Es450 | - | All | All | All |
| Hardware | Sierawireless | Airlink Gx400 | - | All | All | All |
| Hardware | Sierawireless | Airlink Gx400 | - | All | All | All |
| Hardware | Sierawireless | Airlink Gx440 | - | All | All | All |
| Hardware | Sierawireless | Airlink Gx440 | - | All | All | All |
| Hardware | Sierawireless | Airlink Gx450 | - | All | All | All |
| Hardware | Sierawireless | Airlink Gx450 | - | All | All | All |
| Hardware | Sierawireless | Airlink Ls300 | - | All | All | All |
| Hardware | Sierawireless | Airlink Ls300 | - | All | All | All |
| Hardware | Sierawireless | Airlink Lx40 | - | All | All | All |
| Hardware | Sierawireless | Airlink Lx40 | - | All | All | All |
| Hardware | Sierawireless | Airlink Lx60 | - | All | All | All |
| Hardware | Sierawireless | Airlink Lx60 | - | All | All | All |
| Hardware | Sierawireless | Airlink Mp70 | - | All | All | All |
| Hardware | Sierawireless | Airlink Mp70 | - | All | All | All |
| Hardware | Sierawireless | Airlink Mp70e | - | All | All | All |
| Hardware | Sierawireless | Airlink Mp70e | - | All | All | All |
| Hardware | Sierawireless | Airlink Rv50 | - | All | All | All |
| Hardware | Sierawireless | Airlink Rv50 | - | All | All | All |
| Hardware | Sierawireless | Airlink Rv50x | - | All | All | All |
| Hardware | Sierawireless | Airlink Rv50x | - | All | All | All |
| Hardware | Sierrawireless | Airlink Es440 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Es450 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Gx400 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Gx440 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Gx450 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Ls300 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Lx40 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Lx60 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Mp70 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Mp70e | - | All | All | All |
| Hardware | Sierrawireless | Airlink Rv50 | - | All | All | All |
| Hardware | Sierrawireless | Airlink Rv50x | - | All | All | All |
| Operating System | Sierrawireless | Aleos | All | All | All | All |
| Operating System | Sierrawireless | Aleos | All | All | All | All |
| Operating System | Sierrawireless | Aleos | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Sierra Wireless Technical Bulletin - SWI-PSA-2020-004: ALEOS Security Update | MISC | source.sierrawireless.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.