Cleartext Password Storage Vulnerability in Sierra Wireless GX 440 Devices
CVE-2016-5070

9.8CRITICAL

What is CVE-2016-5070?

The Sierra Wireless GX 440 devices employing ALEOS firmware version 4.3.2 exhibit a significant security flaw wherein sensitive user passwords are stored in plaintext. This poses a serious risk, as unauthorized access to the device could enable malicious actors to retrieve these credentials easily. Effective mitigation strategies are crucial to safeguard against potential exploitation and to protect the integrity of user data.

Affected Version(s)

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.