CVE-2023-40462 is a Denial of Service (DoS) vulnerability affecting the ACEManager component of ALEOS 4.16 and earlier, impacting products from Debian and Sierra Wireless. The vulnerability stems from a lack of input sanitization during authentication, allowing an unauthenticated attacker to trigger a DoS condition for ACEManager, though the router's core functions remain unimpaired and ACEManager recovers within ten seconds. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, requiring no user interaction. There is currently no public exploit code available, it is not listed in the KEV catalog, and community discussion and media coverage are minimal, with only one article from BleepingComputer.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.16.0CPE matchmatch criteria | cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
>= 4.10, <= 4.16CPE match | cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* | ||
>= 0, <= 4.9.8CPE match | cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.