Логотип exploitDog
bind:CVE-2023-40460
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-40460

Количество 3

Количество 3

nvd логотип

CVE-2023-40460

около 2 лет назад

The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-fv86-7h6v-h3qg

около 2 лет назад

The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2023-08572

больше 2 лет назад

Уязвимость компонента ACEManager операционной системы ALEOS беспроводных маршрутизаторов Sierra Wireless MP70, RV50x, RV55, LX40, LX60 ES450, GX450, позволяющая нарушителю выполнить произвольные сценарии и вызвать перезагрузку устройства

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-40460

The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-fv86-7h6v-h3qg

The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2023-08572

Уязвимость компонента ACEManager операционной системы ALEOS беспроводных маршрутизаторов Sierra Wireless MP70, RV50x, RV55, LX40, LX60 ES450, GX450, позволяющая нарушителю выполнить произвольные сценарии и вызвать перезагрузку устройства

CVSS3: 7.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу