CVE Database
/

CVE-2018-4070

Back to search

CVE-2018-4070

Published: May 6, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using the /cgi-bin/Embedded_Ace_Get_Task.cgi endpoint.

VendorProductVersions

n/a

Sierra Wireless

affected
Sierra Wireless AirLink ES450 FW 4.9.3

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now