Use of hardcoded certificate and private key
Vulnerability Description
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-40464
Credits & Attribution
No credits recorded in the NVD database.
More from SierraWireless
View All →Affected Vendor
SierraWireless
View all reports →