T
he ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
References
| Link | Resource |
|---|---|
| https://lists.debian.org/debian-lts-announce/2023/12/msg00024.html | Mailing List Third Party Advisory |
| https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006/#sthash.6KUVtE6w.dpbs | Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/12/msg00024.html | Mailing List Third Party Advisory |
| https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006/#sthash.6KUVtE6w.dpbs | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
|
History
13 Feb 2025, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable. |
21 Nov 2024, 08:19
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://lists.debian.org/debian-lts-announce/2023/12/msg00024.html - Mailing List, Third Party Advisory | |
| References | () https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006/#sthash.6KUVtE6w.dpbs - Vendor Advisory |
Information
Published : 2023-12-04 23:15
Updated : 2025-02-13 17:17
NVD link : CVE-2023-40462
Mitre link : CVE-2023-40462
CVE.ORG link : CVE-2023-40462
JSON object : View
CWE
CWE-617
Reachable Assertion