Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-001/ | vendor advisory |
https://www.otorio.com/blog/airlink-acemanager-vulnerabilities/ | third party advisory exploit |
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-04 | third party advisory us government resource |