ZeroHour

CVE-2019-11848

CVSS 3.1
7.2 high
EPSS
1%p63
Published
()
Modified
Description

An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.

Vendors
sierrawireless
Products
aleos
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.