CVE-2023-40464 describes a medium-severity vulnerability in several versions of ALEOS, including ALEOS 4.16.0, and various Sierra Wireless router models. The flaw stems from the use of a hardcoded SSL certificate and private key, which, if compromised, could enable a man-in-the-middle (MitM) attack between ACEManager clients and servers. This vulnerability has a CVSS score of 6.8, indicating a high impact on confidentiality and integrity with high attack complexity, and requires low privileges. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.16.0CPE matchmatch criteria | cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* | ||
>= 4.10, <= 4.16CPE match | cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* | ||
>= 0, <= 4.9.8CPE match | cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.