Mp70
Vendor:
First CVE: May 4, 2018 · Active for 8 years
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mp70 over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 4, 2018
8 years ago
Most Recent CVE
Dec 25, 2023
943 days ago
CVE Severity & Scoring
Mp7013 CVEs
38%
46%
15%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low5 (38.5%)
High3 (23.1%)
None5 (38.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10251CRITICAL A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware be | May 4, 2018 | 9.8 | 32 | NO | NO |
CVE-2019-11851CRITICAL The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary cod | Dec 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-46649HIGH Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device. | Feb 10, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-40459HIGH
The
ACEManager component of ALEOS 4.16 and earlier does not adequately perform
input sanitization during authentication, which could potentially result in a
Denial of Serv | Dec 4, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-46650MEDIUM Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page. | Feb 10, 2023 | 4.9 | 24 | NO | NO |
CVE-2017-15043HIGH A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware be | May 4, 2018 | 8.8 | 23 | NO | NO |
CVE-2023-40462HIGH The ACEManager
component of ALEOS 4.16 and earlier does not
perform input
sanitization during authentication, which could
potentially result
in a Denial of Service (DoS) cond | Dec 4, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-38321HIGH OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Cap | Dec 25, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-40463HIGH
When configured in
debugging mode by an authenticated user with
administrative
privileges, ALEOS 4.16 and earlier store the SHA512
hash of the common
root password | Dec 4, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-40464MEDIUM
Several versions of
ALEOS, including ALEOS 4.16.0, use a hardcoded
SSL certificate and
private key. An attacker with access to these items
could potentially
perform | Dec 4, 2023 | 6.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Mp70
Top CWEs
Versions
No cataloged versions.