CVE-2017-6044
CRITICALSierra Wireless AirLink Raven XE and XT - Unauthenticated Improper Authorization
Title source: llmDescription
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.
References (2)
Core 2
Core References
Third Party Advisory, US Government Resource, VDB Entry x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-115-02
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/98036
Scores
CVSS v3
9.8
EPSS
0.0426
EPSS Percentile
89.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-285
CWE-306
Status
published
Products (3)
n/a/Sierra Wireless AirLink Raven XE and XT
Sierra Wireless AirLink Raven XE and XT
sierra_wireless/airlink_raven_xe_firmware
< -
sierra_wireless/airlink_raven_xt_firmware
Published
Jun 30, 2017
Tracked Since
Feb 18, 2026