PoC Index

CVE-2018-4064

HIGH 7.1EPSS 14.5%

An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS v3.1
7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
CVSS v2.0
5.5 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
EPSS
14.48% chance of exploitation in the next 30 days, 96th percentile
Published
2019-10-31
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related