Aleos
Vendor:
First CVE: Aug 8, 2015 · Active for 10 years
30
Total CVEs
More Total CVEs than 97% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
3.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Aleos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 8, 2015
10 years ago
Most Recent CVE
Dec 25, 2023
946 days ago
CVE Severity & Scoring
Aleos30 CVEs
30%
50%
17%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (20.0%)
Network23 (76.7%)
Unknown1 (3.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (93.3%)
High1 (3.3%)
Unknown1 (3.3%)
User Interaction
None26 (86.7%)
Unknown1 (3.3%)
Required3 (10.0%)
Privileges Required
Low8 (26.7%)
High10 (33.3%)
None11 (36.7%)
Unknown1 (3.3%)
Top CVEs
Signals from CVEs in this product scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-4063HIGH An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a f | May 6, 2019 | 8.8 | 79 | YES | NO |
CVE-2018-10251CRITICAL A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware be | May 4, 2018 | 9.8 | 32 | NO | NO |
CVE-2019-11851CRITICAL The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary cod | Dec 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-8782CRITICAL Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution. | Oct 6, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-11855CRITICAL An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9. | Aug 21, 2020 | 9.8 | 29 | NO | NO |
CVE-2022-46649HIGH Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device. | Feb 10, 2023 | 8.8 | 28 | NO | NO |
CVE-2019-11859HIGH A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root. | Aug 21, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-11852CRITICAL An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed via the ACEviewservice, accessib | Aug 21, 2020 | 9.1 | 27 | NO | NO |
CVE-2019-11862HIGH The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying. | Aug 21, 2020 | 8.4 | 25 | NO | NO |
CVE-2015-2897HIGH Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a ( | Aug 8, 2015 | 10.0 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (30 CVEs).
CISA KEV
1 CVE
3.3% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (30 CVEs).
Media Mentions
Signals from CVEs in this product scope (30 CVEs).
Top CNAs Publishing CVEs For Aleos
Top CWEs
Versions
No cataloged versions.