CVE-2023-40463

HIGH

Sierra Wireless ALEOS < 4.16.0 - Hard-coded Root Password Hash Exposure

Title source: llm
STIX 2.1

Description

When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.

Scores

CVSS v3 8.1
EPSS 0.0063
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
sierrawireless/aleos < 4.16.0
Published Dec 04, 2023
Tracked Since Feb 18, 2026