Loading
Generated remediation guidance and an executive summary. No account required.
An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web server. An attacker can listen to network traffic upstream from the device to capitalize on this vulnerability.
Use CWE-200, Sierrawireless vendor hub and Airlink Es450 Firmware product page to widen CVE-2018-4069 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-4073, CVE-2018-4072 and CVE-2018-4071 for nearby disclosures in the same product family.