PT-2017-16858 · Sierra Wireless · Sierra Wireless Airlink Raven Xe

Publicado

2017-06-30

·

Atualizado

2019-10-09

·

CVE-2017-6044

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sierra Wireless AirLink Raven XE versions prior to 4.0.14 Sierra Wireless AirLink Raven XT versions prior to 4.0.11
Description An issue with improper authorization was found, allowing several files and directories to be accessed without authentication. This could enable a remote attacker to perform sensitive functions, including arbitrary file upload, file download, and device reboot.
Recommendations For Sierra Wireless AirLink Raven XE versions prior to 4.0.14, update to version 4.0.14 or later to resolve the issue. For Sierra Wireless AirLink Raven XT versions prior to 4.0.11, update to version 4.0.11 or later to resolve the issue.

Correção

Missing Authentication

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6044

Produtos afetados

Sierra Wireless Airlink Raven Xe