CVE-2023-40463 - CVE House
Back to Database
Status published High CVE-2023-40463

Use of Hard-Coded Credentials

Vulnerability Description

When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-40463

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

SierraWireless

View all reports →

Affected Software

ALEOS
Vulnerable Versions:
4.10, 0

Timeline

Official Publish: December 4th, 2023
Last Modified: May 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)