ID

VAR-201401-0052


CVE

CVE-2013-2819


TITLE

Sierra Wireless AirLink Raven X EV-DO Gateway Trojan Firmware Installation Vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-001184

DESCRIPTION

The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) update or (2) reprogramming action. AirLink Raven X EV-DO is a small 3G network smart modem. AirLink Raven X EV-DO has an information disclosure vulnerability. Because the program fails to use encryption during the update and reprogramming process, the attacker can reprogram the firmware using the username and password stored in clear text. AirLink Raven X EV-DO is prone to an information-disclosure vulnerability Successful exploits will allow attackers to obtain sensitive information, such as user credentials, that may lead to further attacks

Trust: 2.52

sources: NVD: CVE-2013-2819 // JVNDB: JVNDB-2014-001184 // CNVD: CNVD-2014-00190 // BID: 64702 // VULHUB: VHN-62821

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-00190

AFFECTED PRODUCTS

vendor:sierrawirelessmodel:raven x ev-doscope:eqversion:4221_4.0.11.003

Trust: 1.6

vendor:sierrawirelessmodel:raven x ev-doscope:eqversion:4228_4.0.11.003

Trust: 1.6

vendor:sierrawirelessmodel:airlink mp verizon wifiscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp verizonscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp bell wifiscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp row wifiscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp rowscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:raven xscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:raven xtscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp bellscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:raven xescope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp sprintscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp telus wifiscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp sprint wifiscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:pinpoint xscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:raven x ev-doscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:pinpoint xtscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp telusscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp at\&tscope:eqversion: -

Trust: 1.0

vendor:sierrawirelessmodel:airlink mp at\&t wifiscope:eqversion: -

Trust: 1.0

vendor:sierramodel:airlink mp at&tscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp at&t wifiscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp bellscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp bell wifiscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp rowscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp row wifiscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp sprintscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp sprint wifiscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp telusscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp telus wifiscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp verizonscope: - version: -

Trust: 0.8

vendor:sierramodel:airlink mp verizon wifiscope: - version: -

Trust: 0.8

vendor:sierramodel:pinpooint xscope: - version: -

Trust: 0.8

vendor:sierramodel:pinpooint xtscope: - version: -

Trust: 0.8

vendor:sierramodel:raven xscope: - version: -

Trust: 0.8

vendor:sierramodel:raven x ev-doscope: - version: -

Trust: 0.8

vendor:sierramodel:raven x ev-doscope:eqversion:4221_4.0.11.003

Trust: 0.8

vendor:sierramodel:raven x ev-doscope:eqversion:4228_4.0.11.003

Trust: 0.8

vendor:sierramodel:raven xescope: - version: -

Trust: 0.8

vendor:sierramodel:raven xtscope: - version: -

Trust: 0.8

vendor:sierramodel:wireless airlink raven ev-do 4221 4.0.11.003scope:eqversion:x

Trust: 0.6

vendor:sierramodel:wireless airlink raven ev-do 4228 4.0.11.003scope:eqversion:x

Trust: 0.6

sources: CNVD: CNVD-2014-00190 // JVNDB: JVNDB-2014-001184 // CNNVD: CNNVD-201401-179 // NVD: CVE-2013-2819

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-2819
value: HIGH

Trust: 1.0

NVD: CVE-2013-2819
value: HIGH

Trust: 0.8

CNVD: CNVD-2014-00190
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201401-179
value: CRITICAL

Trust: 0.6

VULHUB: VHN-62821
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-2819
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-00190
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-62821
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-00190 // VULHUB: VHN-62821 // JVNDB: JVNDB-2014-001184 // CNNVD: CNNVD-201401-179 // NVD: CVE-2013-2819

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.9

sources: VULHUB: VHN-62821 // JVNDB: JVNDB-2014-001184 // NVD: CVE-2013-2819

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201401-179

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-201401-179

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001184

PATCH

title:AirLink RavenSecurity Vulnerabilityurl:http://www.sierrawireless.com/resources/support/airlink/docs/raven%20security%20vulnerability%202014-01-10.pdf

Trust: 0.8

title:AirLink Raven X EV-DO Information Disclosure Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/42227

Trust: 0.6

sources: CNVD: CNVD-2014-00190 // JVNDB: JVNDB-2014-001184

EXTERNAL IDS

db:NVDid:CVE-2013-2819

Trust: 3.4

db:ICS CERTid:ICSA-14-007-01A

Trust: 2.5

db:BIDid:64702

Trust: 1.6

db:JVNDBid:JVNDB-2014-001184

Trust: 0.8

db:CNNVDid:CNNVD-201401-179

Trust: 0.7

db:ICS CERTid:ICSA-14-007-01

Trust: 0.6

db:CNVDid:CNVD-2014-00190

Trust: 0.6

db:VULHUBid:VHN-62821

Trust: 0.1

sources: CNVD: CNVD-2014-00190 // VULHUB: VHN-62821 // BID: 64702 // JVNDB: JVNDB-2014-001184 // CNNVD: CNNVD-201401-179 // NVD: CVE-2013-2819

REFERENCES

url:http://ics-cert.us-cert.gov/advisories/icsa-14-007-01a

Trust: 2.5

url:http://www.sierrawireless.com/resources/support/airlink/docs/raven%20security%20vulnerability%202014-01-10.pdf

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-2819

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-2819

Trust: 0.8

url:http://ics-cert.us-cert.gov/advisories/icsa-14-007-01

Trust: 0.6

url:http://www.securityfocus.com/bid/64702

Trust: 0.6

sources: CNVD: CNVD-2014-00190 // VULHUB: VHN-62821 // JVNDB: JVNDB-2014-001184 // CNNVD: CNNVD-201401-179 // NVD: CVE-2013-2819

CREDITS

Cimation

Trust: 0.9

sources: BID: 64702 // CNNVD: CNNVD-201401-179

SOURCES

db:CNVDid:CNVD-2014-00190
db:VULHUBid:VHN-62821
db:BIDid:64702
db:JVNDBid:JVNDB-2014-001184
db:CNNVDid:CNNVD-201401-179
db:NVDid:CVE-2013-2819

LAST UPDATE DATE

2025-04-11T23:04:02.360000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-00190date:2014-01-15T00:00:00
db:VULHUBid:VHN-62821date:2014-01-16T00:00:00
db:BIDid:64702date:2014-07-25T00:47:00
db:JVNDBid:JVNDB-2014-001184date:2014-01-20T00:00:00
db:CNNVDid:CNNVD-201401-179date:2014-01-20T00:00:00
db:NVDid:CVE-2013-2819date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-00190date:2014-01-10T00:00:00
db:VULHUBid:VHN-62821date:2014-01-15T00:00:00
db:BIDid:64702date:2014-01-07T00:00:00
db:JVNDBid:JVNDB-2014-001184date:2014-01-20T00:00:00
db:CNNVDid:CNNVD-201401-179date:2014-01-14T00:00:00
db:NVDid:CVE-2013-2819date:2014-01-15T16:08:13.017