PT-2020-9217 · Aleos · Aleos

Published

2020-08-21

·

Updated

2022-02-09

·

CVE-2019-11856

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions ALEOS versions prior to 4.13.0 ALEOS versions prior to 4.9.5 ALEOS versions prior to 4.4.9
Description A nonce reuse issue exists in the ACEView service, allowing message replay. This can be achieved by capturing traffic to the ACEView service and replaying it to other gateways that share the same credentials.
Recommendations For versions prior to 4.13.0, update to version 4.13.0 or later. For versions prior to 4.9.5, update to version 4.9.5 or later. For versions prior to 4.4.9, update to version 4.4.9 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11856

Affected Products

Aleos