CVE-2017-6044

CRITICAL

Sierra Wireless AirLink Raven XE and XT - Unauthenticated Improper Authorization

Title source: llm
STIX 2.1

Description

An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource, VDB Entry x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-115-02
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98036

Scores

CVSS v3 9.8
EPSS 0.0426
EPSS Percentile 89.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-285 CWE-306
Status published
Products (3)
n/a/Sierra Wireless AirLink Raven XE and XT Sierra Wireless AirLink Raven XE and XT
sierra_wireless/airlink_raven_xe_firmware < -
sierra_wireless/airlink_raven_xt_firmware
Published Jun 30, 2017
Tracked Since Feb 18, 2026