Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded
SSL certificate and private key. An attacker with access to these items
could potentially perform a man in the middle attack between the
ACEManager client and ACEManager server.
The product uses a hard-coded, unchangeable cryptographic key.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Aleos | Sierrawireless | * | 4.16.0 (including) |