CVE-2019-11848
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
21/08/2020
Last modified:
09/02/2022
Description
An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* | 4.13.0 (excluding) | |
cpe:2.3:h:sierrawireless:airlink_lx40:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:sierrawireless:airlink_lx60:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:sierrawireless:airlink_mp70:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:sierrawireless:airlink_mp70e:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:sierrawireless:airlink_rv50:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:sierrawireless:airlink_rv50x:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* | 4.9.5 (excluding) | |
cpe:2.3:h:sierrawireless:airlink_es450:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:sierrawireless:airlink_gx450:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* | 4.4.9 (excluding) | |
cpe:2.3:h:sierrawireless:airlink_es440:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:sierrawireless:airlink_gx400:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:sierrawireless:airlink_gx440:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:sierrawireless:airlink_ls300:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page