7.5
CVSSv3

CVE-2018-4069

Published: 06/05/2019 Updated: 07/05/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web server. An attacker can listen to network traffic upstream from the device to capitalize on this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sierrawireless airlink_es450_firmware 4.9.3

Exploits

An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 493 The ACEManager authentication functionality is done in plaintext XML to the web server An attacker can listen to network traffic upstream from the device to capitalize on this vulnerability ...