CVE-2023-40464Use of Hard-coded Cryptographic Key in Aleos

Severity
6.8MEDIUMNVD
EPSS
0.0%
top 99.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 4
Latest updateSep 13

Description

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages2 packages

CVEListV5sierrawireless/aleos4.104.16

🔴Vulnerability Details

1
GHSA
GHSA-hq59-x6xq-jvxw: Several versions of ALEOS, including ALEOS 42023-12-05

📋Vendor Advisories

1
CISA ICS
Sierra Wireless AirLink with ALEOS firmware2023-12-07

🕵️Threat Intelligence

1
Bleepingcomputer
"Sierra:21" vulnerabilities impact critical infrastructure routers2023-12-06

📄Research Papers

1
arXiv
Automatic Generation of a Cryptography Misuse Taxonomy Using Large Language Models2025-09-13
CVE-2023-40464 — Use of Hard-coded Cryptographic Key | cvebase