Credential Exposure in ALEOS by Sierra Wireless
CVE-2022-46650
4.9MEDIUM
What is CVE-2022-46650?
A vulnerability in ACEManager within ALEOS versions prior to 4.16 enables authenticated users to reconfigure the device, inadvertently exposing ACEManager credentials on the pre-login status page. This flaw presents a significant risk as it may allow unauthorized access to sensitive configurations and compromise the security of affected devices.
Affected Version(s)
ALEOS all versions before 4.16