CVE-2020-8781
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/10/2020
Last modified:
09/02/2022
Description
Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* | 4.11.0 (including) | 4.14.0 (excluding) |
| cpe:2.3:h:sierrawireless:airlink_es440:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_es450:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_gx400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_gx440:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_gx450:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_ls300:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_lx40:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_lx60:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_mp70:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_mp70e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_rv50:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_rv50x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sierrawireless:airlink_rv55:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



