An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.
References
Link | Resource |
---|---|
https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2020-004/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-08-07T00:00:00
Updated: 2020-08-21T18:44:31
Reserved: 2019-05-09T00:00:00
Link: CVE-2019-11848
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-08-21T19:15:11.153
Modified: 2022-02-09T19:26:12.647
Link: CVE-2019-11848
JSON object: View
Redhat Information
No data.
CWE