CVE-2017-6046

HIGH

Sierra Wireless AirLink Raven XE and XT - Insufficiently Protected Credentials

Title source: llm
STIX 2.1

Description

An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently protected during transmission and vulnerable to sniffing, which could lead to information disclosure.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource, VDB Entry x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-115-02
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98036

Scores

CVSS v3 7.5
EPSS 0.0157
EPSS Percentile 72.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200 CWE-522
Status published
Products (3)
n/a/Sierra Wireless AirLink Raven XE and XT Sierra Wireless AirLink Raven XE and XT
sierra_wireless/airlink_raven_xe_firmware < -
sierra_wireless/airlink_raven_xt_firmware
Published Jun 30, 2017
Tracked Since Feb 18, 2026