📦 Aleos

by Sierrawireless

🔍 What is Aleos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-40464

HIGH CVSS 8.1 Dec 4, 2023

This vulnerability in Sierra Wireless ALEOS uses a hardcoded SSL certificate and private key across multiple devices. Attackers who obtain these credentials can perform man-in-the-middle attacks betwe...

CVE-2023-40460

HIGH CVSS 7.1 Dec 4, 2023

This vulnerability in Sierra Wireless ALEOS ACEManager allows authenticated users to upload files without proper validation, potentially executing client-side scripts. This could alter device function...

CVE-2023-40462

HIGH CVSS 7.5 Dec 4, 2023

This vulnerability in Sierra Wireless ALEOS ACEManager allows unauthenticated attackers to cause a temporary denial of service by sending malformed authentication requests. The ACEManager component re...

CVE-2023-40458

HIGH CVSS 7.5 Nov 29, 2023

This CVE describes an infinite loop vulnerability in Sierra Wireless ALEOS ACEManager that allows remote attackers to cause a denial-of-service condition. The DoS affects only the ACEManager service w...

CVE-2022-46649

HIGH CVSS 8.8 Feb 10, 2023

This vulnerability allows authenticated users of Sierra Wireless ALEOS Acemanager to manipulate IP logging operations to execute arbitrary shell commands on affected devices. This is an OS command inj...