Cross-Site Request Forgery in Sierra Wireless AirLink ES450
CVE-2018-4066
What is CVE-2018-4066?
The Sierra Wireless AirLink ES450 device version FW 4.9.3 contains a cross-site request forgery vulnerability in its ACEManager functionality. This security flaw allows an attacker to craft a malicious HTTP request that exploits the authenticated user's session. When a user unknowingly submits these crafted requests, it can result in unauthorized actions being performed on behalf of the user without their consent. This type of attack can lead to serious security implications, as it allows malicious activities to bypass authentication mechanisms.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Sierra Wireless Sierra Wireless AirLink ES450 FW 4.9.3
References
EPSS Score
71% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
