CVE-2023-31279

HIGH

Sierra Wireless AirVantage - Unauthenticated Device Registration and Management via AirVantage Management Service

Title source: llm
STIX 2.1

Description

The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the owner has not disabled the AirVantage Management Service on the devices or registered the device. This could enable an attacker to configure, manage, and execute AT commands on an unsuspecting user’s devices.

Scores

CVSS v3 8.1
EPSS 0.0040
EPSS Percentile 31.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
Sierra Wireless/AirVantage, AirVantage-Capable Devices: All Sierra Wireless devices. Devices not registered in AirVantage with the AirVantage Management Service enabled.
Published Dec 21, 2024
Tracked Since Feb 18, 2026