CVE-2023-40459
HIGH 7.5EPSS 2.3%
TheACEManager component of ALEOS 4.16 and earlier does not adequately performinput sanitization during authentication, which could potentially result in aDenial of Service (DoS) condition for ACEManager without impairing other routerfunctions. ACEManager recovers from the DoS condition by restarting within tenseconds of becoming unavailable.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS
- 2.30% chance of exploitation in the next 30 days, 82th percentile
- Published
- 2023-12-04
- Updated
- 2025-05-29
Proof-of-concept exploits (2)
- 7h3w4lk3r/CVE-2023-404590★ · 2026-06-04
- majidmc2/CVE-2023-404594★ · 2024-02-03