PT-2017-16858 · Sierra Wireless · Sierra Wireless Airlink Raven Xe

Published

2017-06-30

·

Updated

2019-10-09

·

CVE-2017-6044

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sierra Wireless AirLink Raven XE versions prior to 4.0.14 Sierra Wireless AirLink Raven XT versions prior to 4.0.11
Description An issue with improper authorization was found, allowing several files and directories to be accessed without authentication. This could enable a remote attacker to perform sensitive functions, including arbitrary file upload, file download, and device reboot.
Recommendations For Sierra Wireless AirLink Raven XE versions prior to 4.0.14, update to version 4.0.14 or later to resolve the issue. For Sierra Wireless AirLink Raven XT versions prior to 4.0.11, update to version 4.0.11 or later to resolve the issue.

Fix

Missing Authentication

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6044

Affected Products

Sierra Wireless Airlink Raven Xe