10
CVSSv2

CVE-2017-6044

Published: 30/06/2017 Updated: 09/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An Improper Authorization issue exists in Sierra Wireless AirLink Raven XE, all versions before 4.0.14, and AirLink Raven XT, all versions before 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote malicious user to perform sensitive functions including arbitrary file upload, file download, and device reboot.

Vulnerable Product Search on Vulmon Subscribe to Product

sierra_wireless airlink_raven_xe_firmware

sierra_wireless airlink_raven_xt_firmware -