Aleos

Vendor:

First CVE: Aug 8, 2015 · Active for 10 years

30
Total CVEs
More Total CVEs than 97% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
3.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Aleos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 8, 2015
10 years ago
Most Recent CVE
Dec 25, 2023
946 days ago

CVE Severity & Scoring

Aleos30 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local6 (20.0%)
Network23 (76.7%)
Unknown1 (3.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (93.3%)
High1 (3.3%)
Unknown1 (3.3%)
User Interaction
None26 (86.7%)
Unknown1 (3.3%)
Required3 (10.0%)
Privileges Required
Low8 (26.7%)
High10 (33.3%)
None11 (36.7%)
Unknown1 (3.3%)

Top CVEs

Signals from CVEs in this product scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a f
May 6, 20198.879YESNO
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware be
May 4, 20189.832NONO
The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary cod
Dec 26, 20229.831NONO
Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.
Oct 6, 20209.830NONO
An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.
Aug 21, 20209.829NONO
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
Feb 10, 20238.828NONO
A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.
Aug 21, 20208.827NONO
An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed via the ACEviewservice, accessib
Aug 21, 20209.127NONO
The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.
Aug 21, 20208.425NONO
Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (
Aug 8, 201510.025NONO

Exploit Exposure

Signals from CVEs in this product scope (30 CVEs).

CISA KEV
1 CVE
3.3% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (30 CVEs).

Media Mentions

Signals from CVEs in this product scope (30 CVEs).

Top CNAs Publishing CVEs For Aleos

Top CWEs

Versions

No cataloged versions.