8.8
CVSSv3

CVE-2018-4070

Published: 06/05/2019 Updated: 07/05/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using the /cgi-bin/Embedded_Ace_Get_Task.cgi endpoint.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sierrawireless airlink_es450_firmware 4.9.3

Exploits

An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Taskcgi functionality of Sierra Wireless AirLink ES450 FW 493 A specially crafted HTTP request can cause an information disclosure, resulting in the exposure of confidential information, including, but not limited to, plaintext passwords and SNMP communi ...