CVE Vulnerabilities

CVE-2023-40458

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Nov 29, 2023 | Modified: Dec 05, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Aleos Sierrawireless * 4.9.8 (including)
Aleos Sierrawireless 4.10.0 (including) 4.16.2 (including)

References