ID

VAR-201805-0208


CVE

CVE-2017-15043


TITLE

plural Sierra Wireless Vulnerability related to input confirmation in firmware of routers

Trust: 0.8

sources: JVNDB: JVNDB-2017-013383

DESCRIPTION

A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP request to an affected system. plural Sierra Wireless Vulnerability related to input validation exists in the firmware of routers made by the manufacturer.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. SierraWirelessAirLinkGX400 and others are router products of SierraWireless Canada

Trust: 2.25

sources: NVD: CVE-2017-15043 // JVNDB: JVNDB-2017-013383 // CNVD: CNVD-2018-09153 // VULMON: CVE-2017-15043

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-09153

AFFECTED PRODUCTS

vendor:sierrawirelessmodel:gx440scope:ltversion:4.4.5

Trust: 1.0

vendor:sierrawirelessmodel:rv50xscope:ltversion:4.9

Trust: 1.0

vendor:sierrawirelessmodel:rv50scope:ltversion:4.9

Trust: 1.0

vendor:sierrawirelessmodel:ls300scope:ltversion:4.4.5

Trust: 1.0

vendor:sierrawirelessmodel:gx400scope:ltversion:4.4.5

Trust: 1.0

vendor:sierrawirelessmodel:es440scope:ltversion:4.4.5

Trust: 1.0

vendor:sierrawirelessmodel:mp70scope:ltversion:4.9

Trust: 1.0

vendor:sierrawirelessmodel:mp70escope:ltversion:4.9

Trust: 1.0

vendor:sierrawirelessmodel:es450scope:ltversion:4.9

Trust: 1.0

vendor:sierrawirelessmodel:gx450scope:ltversion:4.9

Trust: 1.0

vendor:sierramodel:airlink es440scope:ltversion:4.4.5

Trust: 0.8

vendor:sierramodel:airlink es450scope:ltversion:4.9.3

Trust: 0.8

vendor:sierramodel:airlink gx400scope:ltversion:4.4.5

Trust: 0.8

vendor:sierramodel:airlink gx440scope:ltversion:4.4.5

Trust: 0.8

vendor:sierramodel:airlink gx450scope:ltversion:4.9.3

Trust: 0.8

vendor:sierramodel:airlink ls300scope:ltversion:4.4.5

Trust: 0.8

vendor:sierramodel:airlink mp70scope:ltversion:4.9

Trust: 0.8

vendor:sierramodel:airlink mp70escope:ltversion:4.9

Trust: 0.8

vendor:sierramodel:airlink rv50scope:ltversion:4.9

Trust: 0.8

vendor:sierramodel:airlink rv50xscope:ltversion:4.9

Trust: 0.8

vendor:sierramodel:wireless airlink es440scope:ltversion:4.4.5

Trust: 0.6

vendor:sierramodel:wireless airlink ls300scope:ltversion:4.4.5

Trust: 0.6

vendor:sierramodel:wireless airlink gx450scope:ltversion:4.9

Trust: 0.6

vendor:sierramodel:wireless airlink es450scope:ltversion:4.9

Trust: 0.6

vendor:sierramodel:wireless airlink rv50scope:ltversion:4.9

Trust: 0.6

vendor:sierramodel:wireless airlink rv50xscope:ltversion:4.9

Trust: 0.6

vendor:sierramodel:wireless airlink mp70scope:ltversion:4.9

Trust: 0.6

vendor:sierramodel:wireless airlink mp70escope:ltversion:4.9

Trust: 0.6

vendor:sierramodel:wireless airlink gx400scope:ltversion:4.4.5

Trust: 0.6

vendor:sierramodel:wireless airlink gx440scope:ltversion:4.4.5

Trust: 0.6

sources: CNVD: CNVD-2018-09153 // JVNDB: JVNDB-2017-013383 // NVD: CVE-2017-15043

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-15043
value: HIGH

Trust: 1.0

NVD: CVE-2017-15043
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-09153
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201805-165
value: CRITICAL

Trust: 0.6

VULMON: CVE-2017-15043
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-15043
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2018-09153
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2017-15043
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-09153 // VULMON: CVE-2017-15043 // JVNDB: JVNDB-2017-013383 // CNNVD: CNNVD-201805-165 // NVD: CVE-2017-15043

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.8

sources: JVNDB: JVNDB-2017-013383 // NVD: CVE-2017-15043

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201805-165

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201805-165

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-013383

PATCH

title:SWI-PSA-2018-003: Technical Bulletin - Reaperurl:https://source.sierrawireless.com/resources/airlink/software_reference_docs/technical-bulletin/swi-psa-2018-003-technical-bulletin-reaper/

Trust: 0.8

title:Patches for arbitrary code execution vulnerabilities in various SierraWireless productsurl:https://www.cnvd.org.cn/patchInfo/show/128521

Trust: 0.6

title:Multiple Sierra Wireless Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79876

Trust: 0.6

title:Threatposturl:https://threatpost.com/sierra-wireless-patches-critical-vulns-in-hundreds-of-thousands-of-wireless-routers/131804/

Trust: 0.1

sources: CNVD: CNVD-2018-09153 // VULMON: CVE-2017-15043 // JVNDB: JVNDB-2017-013383 // CNNVD: CNNVD-201805-165

EXTERNAL IDS

db:NVDid:CVE-2017-15043

Trust: 3.1

db:JVNDBid:JVNDB-2017-013383

Trust: 0.8

db:CNVDid:CNVD-2018-09153

Trust: 0.6

db:CNNVDid:CNNVD-201805-165

Trust: 0.6

db:VULMONid:CVE-2017-15043

Trust: 0.1

sources: CNVD: CNVD-2018-09153 // VULMON: CVE-2017-15043 // JVNDB: JVNDB-2017-013383 // CNNVD: CNNVD-201805-165 // NVD: CVE-2017-15043

REFERENCES

url:https://source.sierrawireless.com/resources/airlink/software_reference_docs/technical-bulletin/swi-psa-2018-003-technical-bulletin-reaper/

Trust: 2.3

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-15043

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-15043

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/20.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://threatpost.com/sierra-wireless-patches-critical-vulns-in-hundreds-of-thousands-of-wireless-routers/131804/

Trust: 0.1

sources: CNVD: CNVD-2018-09153 // VULMON: CVE-2017-15043 // JVNDB: JVNDB-2017-013383 // CNNVD: CNNVD-201805-165 // NVD: CVE-2017-15043

SOURCES

db:CNVDid:CNVD-2018-09153
db:VULMONid:CVE-2017-15043
db:JVNDBid:JVNDB-2017-013383
db:CNNVDid:CNNVD-201805-165
db:NVDid:CVE-2017-15043

LAST UPDATE DATE

2024-11-23T23:08:44.102000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-09153date:2018-05-09T00:00:00
db:VULMONid:CVE-2017-15043date:2018-06-13T00:00:00
db:JVNDBid:JVNDB-2017-013383date:2018-06-29T00:00:00
db:CNNVDid:CNNVD-201805-165date:2018-05-07T00:00:00
db:NVDid:CVE-2017-15043date:2024-11-21T03:13:59.653

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-09153date:2018-05-09T00:00:00
db:VULMONid:CVE-2017-15043date:2018-05-04T00:00:00
db:JVNDBid:JVNDB-2017-013383date:2018-06-29T00:00:00
db:CNNVDid:CNNVD-201805-165date:2018-05-07T00:00:00
db:NVDid:CVE-2017-15043date:2018-05-04T20:29:00.437