Vulnerabilities > Sierrawireless

DATE CVE VULNERABILITY TITLE RISK
2017-04-10 CVE-2016-5066 Credentials Management vulnerability in Sierrawireless Aleos Firmware 4.3.2
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user.
network
low complexity
sierrawireless CWE-255
critical
9.8
2017-04-10 CVE-2016-5065 Command Injection vulnerability in Sierrawireless Aleos Firmware 4.3.2
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection.
network
low complexity
sierrawireless CWE-77
critical
9.8
2016-04-21 CVE-2015-6479 Unspecified vulnerability in Sierrawireless Aleos
ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspecified vectors.
network
low complexity
sierrawireless
4.3