CVE-2023-40462
Improper input leads to DoS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The ACEManager
component of ALEOS 4.16 and earlier does not perform input
sanitization during authentication, which could potentially result
in a Denial of Service (DoS) condition for ACEManager without
impairing other router functions. ACEManager recovers from the
DoS condition by restarting within ten seconds of becoming
unavailable.
El componente ACEManager de ALEOS 4.16 y versiones anteriores no realiza sanitización de entrada durante la autenticación, lo que podría resultar en una condición de denegación de servicio (DoS) para ACEManager sin afectar otras funciones del router. ACEManager se recupera de la condición DoS reiniciándose dentro de los diez segundos posteriores a que no esté disponible.
The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-08-14 CVE Reserved
- 2023-12-04 CVE Published
- 2025-02-13 CVE Updated
- 2025-06-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-617: Reachable Assertion
CAPEC
- CAPEC-153: Input Data Manipulation
References (2)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/12/msg00024.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sierrawireless Search vendor "Sierrawireless" | Aleos Search vendor "Sierrawireless" for product "Aleos" | <= 4.16.0 Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.16.0" | - |
Affected
| in | Sierrawireless Search vendor "Sierrawireless" | Es450 Search vendor "Sierrawireless" for product "Es450" | - | - |
Safe
|
Sierrawireless Search vendor "Sierrawireless" | Aleos Search vendor "Sierrawireless" for product "Aleos" | <= 4.16.0 Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.16.0" | - |
Affected
| in | Sierrawireless Search vendor "Sierrawireless" | Gx450 Search vendor "Sierrawireless" for product "Gx450" | - | - |
Safe
|
Sierrawireless Search vendor "Sierrawireless" | Aleos Search vendor "Sierrawireless" for product "Aleos" | <= 4.16.0 Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.16.0" | - |
Affected
| in | Sierrawireless Search vendor "Sierrawireless" | Lx40 Search vendor "Sierrawireless" for product "Lx40" | - | - |
Safe
|
Sierrawireless Search vendor "Sierrawireless" | Aleos Search vendor "Sierrawireless" for product "Aleos" | <= 4.16.0 Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.16.0" | - |
Affected
| in | Sierrawireless Search vendor "Sierrawireless" | Lx60 Search vendor "Sierrawireless" for product "Lx60" | - | - |
Safe
|
Sierrawireless Search vendor "Sierrawireless" | Aleos Search vendor "Sierrawireless" for product "Aleos" | <= 4.16.0 Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.16.0" | - |
Affected
| in | Sierrawireless Search vendor "Sierrawireless" | Mp70 Search vendor "Sierrawireless" for product "Mp70" | - | - |
Safe
|
Sierrawireless Search vendor "Sierrawireless" | Aleos Search vendor "Sierrawireless" for product "Aleos" | <= 4.16.0 Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.16.0" | - |
Affected
| in | Sierrawireless Search vendor "Sierrawireless" | Rv50x Search vendor "Sierrawireless" for product "Rv50x" | - | - |
Safe
|
Sierrawireless Search vendor "Sierrawireless" | Aleos Search vendor "Sierrawireless" for product "Aleos" | <= 4.16.0 Search vendor "Sierrawireless" for product "Aleos" and version " <= 4.16.0" | - |
Affected
| in | Sierrawireless Search vendor "Sierrawireless" | Rv55 Search vendor "Sierrawireless" for product "Rv55" | - | - |
Safe
|
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|