CVE-2019-11862Incorrect Authorization in Aleos

Severity
8.4HIGHNVD
EPSS
0.0%
top 98.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 21
Latest updateMay 24

Description

The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages1 packages

NVDsierrawireless/aleos4.9.04.9.5+1

🔴Vulnerability Details

1
GHSA
GHSA-9cvc-6538-66j6: The SSH service on ALEOS before 42022-05-24
CVE-2019-11862 — Incorrect Authorization in Aleos | cvebase