Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded
SSL certificate and private key. An attacker with access to these items
could potentially perform a man in the middle attack between the
ACEManager client and ACEManager server.
The product uses a hard-coded, unchangeable cryptographic key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Aleos | Sierrawireless | * | 4.16.0 (including) |