mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
19 lines
1012 B
Markdown
19 lines
1012 B
Markdown
### [CVE-2023-40459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40459)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
TheACEManager component of ALEOS 4.16 and earlier does not adequately performinput sanitization during authentication, which could potentially result in aDenial of Service (DoS) condition for ACEManager without impairing other routerfunctions. ACEManager recovers from the DoS condition by restarting within tenseconds of becoming unavailable.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006/#sthash.6KUVtE6w.dpbs
|
|
|
|
#### Github
|
|
- https://github.com/majidmc2/CVE-2023-40459
|
|
- https://github.com/nomi-sec/PoC-in-GitHub
|
|
|