Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-001/ | vendor advisory |
https://www.otorio.com/blog/airlink-acemanager-vulnerabilities/ | third party advisory exploit |
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-04 | third party advisory us government resource |