The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.
References
Link | Resource |
---|---|
http://source.sierrawireless.com/-/media/support_downloads/security-bulletins/pdf/swi-psa-2021-001.ashx | Vendor Advisory |
https://www.sierrawireless.com/company/security/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Information
Published : 2022-12-26 14:15
Updated : 2023-01-05 18:00
NVD link : CVE-2019-11851
Mitre link : CVE-2019-11851
JSON object : View
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Products Affected
sierrawireless
- aleos
- lx40
- mp70e
- es440
- lx60
- rv50x
- ls300
- es450
- rv50
- gx450
- mp70
- gx440
- gx400