Sierra Wireless AirLink ALEOS (Update B)


2020-04-23 14:00:27 UTC


This updated advisory is a follow-up to the original advisory titled ICSA-19-122-03 Sierra Wireless AirLink ALEOS (Update A) that was published August 20, 2019, to the ICS webpage on This updated advisory includes mitigations for OS command injection, use of hard-coded credentials, unrestricted upload of file with dangerous type, cross-site scripting, cross-site request forgery, information exposure, and missing encryption of sensitive data vulnerabilities reported in the Sierra Wireless AirLink ALEOS products.