Improper input leads to DoS
CVE-2023-40462

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
4 December 2023

What is CVE-2023-40462?

The ACEManager component in ALEOS 4.16 and earlier versions is susceptible to a Denial of Service (DoS) due to inadequate input sanitization during the authentication process. This vulnerability can cause ACEManager to become temporarily unavailable, though it does not affect the overall functionality of the router. The system is capable of recovering from the DoS condition automatically, restarting within ten seconds after it becomes unresponsive.

Affected Version(s)

ALEOS 4.10 <= 4.16

ALEOS 0 <= 4.9.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.