VendorsSierra Wirelessairlink_lx60any version
Vulnerabilities

Sierra Wireless Airlink LX60 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2020-8782
ALEOS LAN-Side RPC Service Remote Code Execution
Published 2020-10-06 · Modified
9.8EPSS 0.018
CVE-2019-11855
ALEOS LAN-Side RPC Server
Published 2020-08-21 · Modified
9.8EPSS 0.012
CVE-2019-11857
ALEOS AceManager Information Disclosure
Published 2020-08-21 · Modified
9.1EPSS 0.021
CVE-2019-11852
ALEOS ACEView Service Out-Of-Bounds Read
Published 2020-08-21 · Modified
9.1EPSS 0.009
CVE-2018-4063
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Published 2019-05-06 · Analyzed
9.0KEVEPSS 0.271
CVE-2019-11859
ALEOS SMS Handler Buffer Overflow
Published 2020-08-21 · Modified
9.0EPSS 0.020
CVE-2019-11862
ALEOS SSH Service Allows Traffic Proxying
Published 2020-08-21 · Modified
8.4EPSS 0.007
CVE-2020-8781
Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.
Published 2020-10-06 · Modified
7.8EPSS 0.005
CVE-2019-11847
ALEOS User Root Shell Escalation
Published 2020-08-21 · Modified
7.8EPSS 0.004
CVE-2019-11853
ALEOS AT Command Injections
Published 2020-08-21 · Modified
7.2EPSS 0.012
CVE-2019-11858
ALEOS Multiple Web UI vulnerabilities
Published 2020-08-21 · Modified
7.2EPSS 0.011
CVE-2019-11848
ALEOS AT Command API Abuse
Published 2020-08-21 · Modified
7.2EPSS 0.011
CVE-2019-11849
ALEOS AT API Stack Overflow
Published 2020-08-21 · Modified
6.7EPSS 0.004
CVE-2019-11850
ALEOS AT Command Stack Overflow
Published 2020-08-21 · Modified
6.7EPSS 0.004
CVE-2019-11856
ALEOS ACEView Message Replay
Published 2020-08-21 · Modified
5.5EPSS 0.010