CVE-2015-2897: Sierra Wireless ALEOS
High severity, CVSS 10.0. EPSS: 2.3% chance of exploitation in the next 30 days.
Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session.
Affected products
- Sierra Wireless ALEOS: up to and including 4.4.1
Published 2015-08-08. Last modified 2026-06-17.