EXPOSURES › CVE-2018-4063
CVE-2018-4063
HIGH ⌖ ON CISA KEV · EXPLOITEDSierra Wireless AirLink ALEOS exposed unrestricted upload of executable files, leading to potential remote code execution.
Sierra Wireless AirLink ALEOS allowed unauthorized uploads of executable files, which could be exploited remotely to execute code, putting DIB systems at risk. Users were advised to stop using the product.
Shame score — Unrestricted upload of executable files leading to remote code execution, with the product being end-of-life and end-of-service.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.