356
VMScore

CVE-2018-4067

Published: 06/05/2019 Updated: 07/05/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a information leak, resulting in the disclosure of internal paths and files. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sierrawireless airlink_es450_firmware 4.9.3

Exploits

An exploitable information disclosure vulnerability exists in the ACEManager template_loadcgi functionality of Sierra Wireless AirLink ES450 FW 493 A specially crafted HTTP request can cause a information leak, resulting in the disclosure of internal paths and files An attacker can make an authenticated HTTP request to trigger this vulnerabili ...