CVE-2023-40462

HIGH

Sierrawireless Aleos < 4.16.0 - Reachable Assertion

Title source: rule
STIX 2.1

Description

The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.

Scores

CVSS v3 7.5
EPSS 0.0001
EPSS Percentile 1.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (2)
debian/debian_linux 10.0
sierrawireless/aleos < 4.16.0
Published Dec 04, 2023
Tracked Since Feb 18, 2026