PT-2022-8078 · Sierra Wireless · Sierra Wireless Aleos

CVE-2019-11851

·

Published

2022-12-26

·

Updated

2023-01-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sierra Wireless ALEOS versions prior to 4.4.9 Sierra Wireless ALEOS versions 4.5.x through 4.9.x before 4.9.5 Sierra Wireless ALEOS versions 4.10.x through 4.13.x before 4.14.0
Description The ACENet service in Sierra Wireless ALEOS allows remote attackers to execute arbitrary code via a buffer overflow.
Recommendations For versions prior to 4.4.9, update to version 4.4.9 or later. For versions 4.5.x through 4.9.x, update to version 4.9.5 or later. For versions 4.10.x through 4.13.x, update to version 4.14.0 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11851

Affected Products

Sierra Wireless Aleos