ID

VAR-E-201501-0484


CVE

cve_id:CVE-2015-2054

Trust: 0.3

sources: BID: 74875

TITLE

Sierra Wireless AirCard 'export.cfg' HTTP Header Injection Vulnerability

Trust: 0.3

sources: BID: 74875

DESCRIPTION

Sierra Wireless AirCard is prone to an HTTP header-injection vulnerability.
A successful attack may allow attackers to insert a crafted HTTP header into an HTTP response that could cause a web page redirection to a possible malicious website; this may aid in launching further attacks.
Sierra Wireless AirCard versions 760S, 762S, and 763S are vulnerable.

Trust: 0.3

sources: BID: 74875

AFFECTED PRODUCTS

vendor:sierramodel:wireless aircard 763sscope: - version: -

Trust: 0.3

vendor:sierramodel:wireless aircard 762sscope: - version: -

Trust: 0.3

vendor:sierramodel:wireless aircard 760sscope: - version: -

Trust: 0.3

sources: BID: 74875

EXPLOIT

The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.

Trust: 0.3

sources: BID: 74875

PRICE

Free

Trust: 0.3

sources: BID: 74875

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 74875

CREDITS

Luke Walker

Trust: 0.3

sources: BID: 74875

EXTERNAL IDS

db:NVDid:CVE-2015-2054

Trust: 0.3

db:BIDid:74875

Trust: 0.3

sources: BID: 74875

REFERENCES

url:http://www.sierrawireless.com/

Trust: 0.3

url:http://seclists.org/fulldisclosure/2015/jan/58

Trust: 0.3

sources: BID: 74875

SOURCES

db:BIDid:74875

LAST UPDATE DATE

2022-07-27T09:15:31.378000+00:00


SOURCES UPDATE DATE

db:BIDid:74875date:2015-01-14T00:00:00

SOURCES RELEASE DATE

db:BIDid:74875date:2015-01-14T00:00:00