CVE-2023-38321NULL Pointer Dereference in Aleos

Severity
7.5HIGHNVD
EPSS
0.1%
top 83.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 25

Description

OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDsierrawireless/aleos< 4.17.0.12
Debianopennds/opennds< 10.2.0+dfsg-1+1

🔴Vulnerability Details

3
CVEList
CVE-2023-38321: OpenNDS, as used in Sierra Wireless ALEOS before 42023-12-25
GHSA
GHSA-7246-m99m-q4pq: OpenNDS, as used in Sierra Wireless ALEOS before 42023-12-25
OSV
CVE-2023-38321: OpenNDS, as used in Sierra Wireless ALEOS before 42023-12-25

📋Vendor Advisories

1
Debian
CVE-2023-38321: opennds - OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, a...2023