CVE-2017-6044
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including arbitrary file upload, file download, and device reboot.
Published:Jun 30, 2017
Last Modified:Apr 20, 2025
EPS:Jun 30, 2017
EPSS Score:0.0769
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Sierra Wireless
Product
Airlink Raven Xe
Sierra Wireless
Airlink Raven Xe
Vendor
Sierra Wireless
Product
Airlink Raven Xe Firmware
Sierra Wireless
Airlink Raven Xe Firmware
Vendor
Sierra Wireless
Product
Airlink Raven Xt
Sierra Wireless
Airlink Raven Xt
Vendor
Sierra Wireless
Product
Airlink Raven Xt Firmware
Sierra Wireless
Airlink Raven Xt Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
