PT-2018-5753 · Sierra Wireless · Sierra Wireless Airlink Rv50+5
Publicado
2018-05-04
·
Atualizado
2018-06-13
·
CVE-2017-15043
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers versions prior to 4.4.5
Sierra Wireless AirLink GX450, ES450, RV50, RV50X, MP70, and MP70E routers versions prior to 4.9
Description:
The issue is caused by insufficient input validation on user-controlled input in an HTTP request to the targeted device. An authenticated remote attacker could exploit this by sending a crafted HTTP request to gain full control of an affected system, including issuing commands with root privileges.
Recommendations:
For Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5, update to firmware version 4.4.5 or later.
For Sierra Wireless AirLink GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9, update to firmware version 4.9 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sierra Wireless Airlink Es440
Sierra Wireless Airlink Es450
Sierra Wireless Airlink Gx400
Sierra Wireless Airlink Ls300
Sierra Wireless Airlink Mp70
Sierra Wireless Airlink Rv50