Critical Infrastructure Sectors: Commercial Facilities, Communications, Energy, Government Facilities, Transportation Systems, Water and Wastewater Systems
The ACEManager component of ALEOS 4.16 and previous versions does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sierrawireless aleos |