8.8
CVSSv3

CVE-2018-4061

Published: 06/05/2019 Updated: 07/05/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution. An attacker can send an authenticated HTTP request to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sierrawireless airlink_es450_firmware 4.9.3

Exploits

An exploitable command injection vulnerability exists in the ACEManager iploggingcgi functionality of Sierra Wireless AirLink ES450 FW 493 A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution An attacker can send an authenticated HTTP request to trigger this vulnerability ...