- Description
- ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspecified vectors.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
- Hype score
- Not currently trending
- Comment
- CWE-538: File and Directory Information Exposure
- Impact
- -
- Solution
- -
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sierrawireless:es440:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E2098BAB-AF80-4C32-A5B8-FD6296C74110"
},
{
"criteria": "cpe:2.3:h:sierrawireless:es450:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "524DF1AE-21F2-4AA6-99E7-6F98304FF845"
},
{
"criteria": "cpe:2.3:h:sierrawireless:gx400:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5CBA7B93-E1C2-41C6-B21E-6DA8B568D751"
},
{
"criteria": "cpe:2.3:h:sierrawireless:gx440:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "15DD2CF2-3A83-4ED7-BCD8-05F60782AE17"
},
{
"criteria": "cpe:2.3:h:sierrawireless:gx450:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2C12CF71-FE0E-44EA-9F2E-7CFB42E7C216"
},
{
"criteria": "cpe:2.3:h:sierrawireless:ls300:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5F4A4F52-F99E-4F72-8A2C-8D2CC21461BD"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30FB5223-A3DD-4914-8BEC-D2486E3B31E5",
"versionEndIncluding": "4.4.2"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]