CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
9.1 CRITICAL
An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed via the ACEviewservice, accessible by default on the LAN.
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2023-01-06
N/A
9.8 CRITICAL
The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.
Airlink Lx40, Airlink Lx60, Airlink Mp70, Airlink Mp70e, Airlink Rv50, Airlink Rv50x, Aleos, Sierrawireless
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
6.7 MEDIUM
A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution
An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.
Airlink Lx40, Airlink Lx60, Airlink Mp70, Airlink Mp70e, Airlink Rv50, Airlink Rv50x, Aleos, Sierrawireless
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
6.7 MEDIUM
A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code execution.
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2022-02-09
N/A
7.2 HIGH
An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.
Aleos, Airlink_lx40, Airlink_lx60, Airlink_mp70, Airlink_mp70e, Airlink_rv50, Airlink_rv50x, Airlink_es450, Airlink_gx450, Airlink_es440
2020-10-19
N/A
7.8 HIGH
An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.
/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2020-08-24
N/A
6.1 MEDIUM
An HTML Injection vulnerability has been discovered on the RICOH SP 4510DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
Sp_4520dn_firmware, Sp_4520dn, Sp_4510dn_firmware, Sp_4510dn, Sp_c250sf_firmware, Sp_c250sf, Sp_c252sf_firmware, Sp_c252sf, Sp_c250dn_firmware, Sp_c250dn
2020-08-24
N/A
6.1 MEDIUM
An HTML Injection vulnerability has been discovered on the RICOH SP 4520DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn or entryDisplayNameIn parameter.
