PT-2022-8078 · Sierra Wireless · Sierra Wireless Aleos

Published

2022-12-26

·

Updated

2023-01-06

·

CVE-2019-11851

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sierra Wireless ALEOS versions prior to 4.4.9 Sierra Wireless ALEOS versions 4.5.x through 4.9.x before 4.9.5 Sierra Wireless ALEOS versions 4.10.x through 4.13.x before 4.14.0
Description The ACENet service in Sierra Wireless ALEOS allows remote attackers to execute arbitrary code via a buffer overflow.
Recommendations For versions prior to 4.4.9, update to version 4.4.9 or later. For versions 4.5.x through 4.9.x, update to version 4.9.5 or later. For versions 4.10.x through 4.13.x, update to version 4.14.0 or later.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2019-11851

Affected Products

Sierra Wireless Aleos