peter bassill · operator
$ cve CVE-2017-6044 JSON

CVE-2017-6044

9.8
CRITICAL · CVSS 3.0 · EPSS 4.3% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.26% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-285
On CISA KEVno
Public exploitnone known
Published2017-06-30
Last modified2026-06-17

Affected (4)

VendorProduct
sierra wirelessairlink raven xe
sierra wirelessairlink raven xe firmware
sierra wirelessairlink raven xt
sierra wirelessairlink raven xt firmware

References

→ the Explorer  ·  watch your stack  ·  NVD