OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Aleos | Sierrawireless | * | 4.17.0.12 (excluding) |
Opennds | Ubuntu | bionic | * |
Opennds | Ubuntu | lunar | * |
Opennds | Ubuntu | mantic | * |
Opennds | Ubuntu | trusty | * |
Opennds | Ubuntu | xenial | * |