// For flags

CVE-2015-2897

 

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session.

Vulnerabilidad en Sierra Wireless ALEOS en versiones anteriores a 4.4.2 en dispositivos AirLink ES, GXy LS, tiene cuentas root embebidas, lo que facilita a atacantes remotos obtener acceso administrativo a través de (1) SSH o (2) sesión TELNET.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-04-03 CVE Reserved
  • 2015-08-08 CVE Published
  • 2023-05-30 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL Tag Source
http://www.kb.cert.org/vuls/id/628568 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sierrawireless
Search vendor "Sierrawireless"
Aleos
Search vendor "Sierrawireless" for product "Aleos"
<= 4.4.1
Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.4.1"
-
Affected
in Sierrawireless
Search vendor "Sierrawireless"
Airlink Es440
Search vendor "Sierrawireless" for product "Airlink Es440"
*-
Safe
Sierrawireless
Search vendor "Sierrawireless"
Aleos
Search vendor "Sierrawireless" for product "Aleos"
<= 4.4.1
Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.4.1"
-
Affected
in Sierrawireless
Search vendor "Sierrawireless"
Airlink Es450
Search vendor "Sierrawireless" for product "Airlink Es450"
*-
Safe
Sierrawireless
Search vendor "Sierrawireless"
Aleos
Search vendor "Sierrawireless" for product "Aleos"
<= 4.4.1
Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.4.1"
-
Affected
in Sierrawireless
Search vendor "Sierrawireless"
Airlink Gx440
Search vendor "Sierrawireless" for product "Airlink Gx440"
*-
Safe
Sierrawireless
Search vendor "Sierrawireless"
Aleos
Search vendor "Sierrawireless" for product "Aleos"
<= 4.4.1
Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.4.1"
-
Affected
in Sierrawireless
Search vendor "Sierrawireless"
Airlink Gx450
Search vendor "Sierrawireless" for product "Airlink Gx450"
*-
Safe
Sierrawireless
Search vendor "Sierrawireless"
Aleos
Search vendor "Sierrawireless" for product "Aleos"
<= 4.4.1
Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.4.1"
-
Affected
in Sierrawireless
Search vendor "Sierrawireless"
Airlink Ls300
Search vendor "Sierrawireless" for product "Airlink Ls300"
*-
Safe