ZeroHour

CVE-2018-4068

CVSS 3.0
5.3 medium
EPSS
11%p96
Published
()
Modified
Description

An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request can result in disclosure of the default configuration for the device. An attacker can send an unauthenticated HTTP request to trigger this vulnerability.

Vendors
sierrawireless
Products
airlink es450 firmware
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news