PT-2018-5753 · Sierra Wireless · Sierra Wireless Airlink Rv50+5

Publicado

2018-05-04

·

Atualizado

2018-06-13

·

CVE-2017-15043

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers versions prior to 4.4.5 Sierra Wireless AirLink GX450, ES450, RV50, RV50X, MP70, and MP70E routers versions prior to 4.9
Description: The issue is caused by insufficient input validation on user-controlled input in an HTTP request to the targeted device. An authenticated remote attacker could exploit this by sending a crafted HTTP request to gain full control of an affected system, including issuing commands with root privileges.
Recommendations: For Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5, update to firmware version 4.4.5 or later. For Sierra Wireless AirLink GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9, update to firmware version 4.9 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15043

Produtos afetados

Sierra Wireless Airlink Es440
Sierra Wireless Airlink Es450
Sierra Wireless Airlink Gx400
Sierra Wireless Airlink Ls300
Sierra Wireless Airlink Mp70
Sierra Wireless Airlink Rv50