Remote Code Execution in Sierra Wireless GX 440 by ALEOS Firmware
CVE-2016-5071

8.8HIGH

What is CVE-2016-5071?

Sierra Wireless GX 440 devices running ALEOS firmware version 4.3.2 are susceptible to a serious vulnerability that allows for remote code execution by executing the management web application with root privileges. This means that an attacker could gain unauthorized access to the device, potentially leading to further exploitation within the network.

Affected Version(s)

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.