CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
See.sys, up to version 4.25, in SoftEther VPN Server versions 4.29 or older, allows a user to call an IOCTL specifying any kernel address to which arbitrary bytes are written to.
Realtek NDIS driver rt640x64.sys, file version 10.1.505.2015, fails to do any size checking on an input buffer from user space, which the driver assumes has a size greater than zero bytes. To exploit this vulnerability, an attacker must send an IRP with a system buffer size of 0.
Airlink Es440, Airlink Es450, Airlink Gx400, Airlink Gx440, Airlink Gx450, Airlink Ls300, Airlink Lx40, Airlink Lx60, Airlink Mp70, Airlink Mp70e, Airlink Rv50, Airlink Rv50x, Aleos, Sierrawireless
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2021-07-21
N/A
8.4 HIGH
The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.
An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1179, CVE-2019-1180, CVE-2019-1184.
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
8.8 HIGH
A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
7.2 HIGH
Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
4.9 MEDIUM
Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
3.8 LOW
A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
9.8 CRITICAL
An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
7.2 HIGH
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
