Security Advisory

CVE-2018-4068

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-05-06 17:50:44
Last updated 2024-08-05 05:04:29
Assigner talos
CVSS score not scored
State PUBLISHED

Description

An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request can result in disclosure of the default configuration for the device. An attacker can send an unauthenticated HTTP request to trigger this vulnerability.