Vulnerability Description
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sierrawireless | Aleos | < 4.4.9 |
| Sierrawireless | Airlink Es440 | - |
| Sierrawireless | Airlink Gx400 | - |
| Sierrawireless | Airlink Gx440 | - |
| Sierrawireless | Airlink Ls300 | - |
| Sierrawireless | Airlink Lx40 | - |
| Sierrawireless | Airlink Lx60 | - |
| Sierrawireless | Airlink Mp70 | - |
| Sierrawireless | Airlink Mp70E | - |
| Sierrawireless | Airlink Rv50 | - |
| Sierrawireless | Airlink Rv50X | - |
| Sierrawireless | Airlink Es450 | - |
| Sierrawireless | Airlink Gx450 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/152648/Sierra-Wireless-AirLink-ES450-ACEManExploitVDB Entry
- http://www.securityfocus.com/bid/108147Broken Link
- https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03Third Party AdvisoryUS Government Resource
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0748ExploitThird Party Advisory
- http://packetstormsecurity.com/files/152648/Sierra-Wireless-AirLink-ES450-ACEManExploitVDB Entry
- http://www.securityfocus.com/bid/108147Broken Link
- https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03Third Party AdvisoryUS Government Resource
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0748ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-US Government Resource
- https://www.forescout.com/blog/ot-network-security-threats-industrial-routers-unExploitThird Party Advisory
FAQ
What is CVE-2018-4063?
CVE-2018-4063 is a vulnerability with a CVSS score of 8.8 (HIGH). An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in ex...
How severe is CVE-2018-4063?
CVE-2018-4063 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-4063?
Check the references section above for vendor advisories and patch information. Affected products include: Sierrawireless Aleos, Sierrawireless Airlink Es440, Sierrawireless Airlink Gx400, Sierrawireless Airlink Gx440, Sierrawireless Airlink Ls300.