SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-4066

An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3.

HIGH 8.8EPSS 1.91%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated requests being requested through an authenticated user. An attacker can get an authenticated user to request authenticated pages on the attacker's behalf to trigger this vulnerability.

CVSS 3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
1.91% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
sierrawireless/airlink es450 firmware
Source
talos-cna@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.