CVE-2023-40460
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
04/12/2023
Last modified:
08/12/2023
Description
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
The ACEManager<br />
component of ALEOS 4.16 and earlier does not<br />
<br />
<br />
<br />
validate uploaded<br />
file names and types, which could potentially allow<br />
<br />
<br />
<br />
an authenticated<br />
user to perform client-side script execution within<br />
<br />
<br />
<br />
ACEManager, altering<br />
the device functionality until the device is<br />
<br />
<br />
<br />
restarted.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* | 4.16.0 (including) | |
| cpe:2.3:h:sierrawireless:es450:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:gx450:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:lx40:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:lx60:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:mp70:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:rv50x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:rv55:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



