Known Vulnerabilities for Aleos by Sierrawireless
Listed below are 10 of the newest known vulnerabilities associated with "Aleos" by "Sierrawireless".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-40462 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-12-04 | 2024-02-02 |
| CVE-2023-40458 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-11-29 | 2023-12-05 |
| CVE-2023-38321 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-12-25 | 2024-01-03 |
| CVE-2022-46650 json | Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManag... | 4.9 - MEDIUM | 2023-02-10 | 2023-02-16 |
| CVE-2022-46649 json | Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execut... | 8.8 - HIGH | 2023-02-10 | 2023-02-16 |
| CVE-2020-8782 json | Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution. | 9.8 - CRITICAL | 2020-10-06 | 2022-02-09 |
| CVE-2020-8781 json | Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privileg... | 7.8 - HIGH | 2020-10-06 | 2022-02-09 |
| CVE-2019-11862 json | The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying. | 8.4 - HIGH | 2020-08-21 | 2021-07-21 |
| CVE-2019-11859 json | A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root. | 8.8 - HIGH | 2020-08-21 | 2022-02-09 |
| CVE-2019-11858 json | Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9. | 7.2 - HIGH | 2020-08-21 | 2022-02-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Sierrawireless | Aleos | 4.9.4 | |||
| Operating System | Sierrawireless | Aleos | 4.9.3 | |||
| Operating System | Sierrawireless | Aleos | 4.9.2 | |||
| Operating System | Sierrawireless | Aleos | 4.9.1 | |||
| Operating System | Sierrawireless | Aleos | 4.9.0 | |||
| Operating System | Sierrawireless | Aleos | 4.8.1 | |||
| Operating System | Sierrawireless | Aleos | 4.8.0 | |||
| Operating System | Sierrawireless | Aleos | 4.7.0 | |||
| Operating System | Sierrawireless | Aleos | 4.6.2 | |||
| Operating System | Sierrawireless | Aleos | 4.6.1 | |||
| Operating System | Sierrawireless | Aleos | 4.6.0 | |||
| Operating System | Sierrawireless | Aleos | 4.5.2 | |||
| Operating System | Sierrawireless | Aleos | 4.5.1 | |||
| Operating System | Sierrawireless | Aleos | 4.5.0 | |||
| Operating System | Sierrawireless | Aleos | 4.4.9 | |||
| Operating System | Sierrawireless | Aleos | 4.4.8 | |||
| Operating System | Sierrawireless | Aleos | 4.4.7 | |||
| Operating System | Sierrawireless | Aleos | 4.4.6 | |||
| Operating System | Sierrawireless | Aleos | 4.4.5 | |||
| Operating System | Sierrawireless | Aleos | 4.4.4 |